Skip to content

Commit 875712c

Browse files
committed
fix: rework SBOM generation
1 parent e114787 commit 875712c

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

.github/workflows/release.yaml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -66,13 +66,16 @@ jobs:
6666
- uses: sigstore/cosign-installer@e1523de7571e31dbe865fd2e80c5c7c23ae71eb4 # v3.4.0
6767
- uses: advanced-security/sbom-generator-action@375dee8e6144d9fd0ec1f5667b4f6fb4faacefed # v0.0.1
6868
id: sbom
69-
working-directory: /tmp
7069
env:
7170
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
71+
- name: Move sbom to avoid dirty git
72+
run: mv "$GITHUB_SBOM_PATH" /tmp/sbom/spdx.json
73+
env:
74+
GITHUB_SBOM_PATH: ${{ steps.sbom.outputs.fileName }}
7275
- uses: goreleaser/goreleaser-action@7ec5c2b0c6cdda6e8bbb49444bc797dd33d74dd8 # v5.0.0
7376
with:
7477
version: latest
7578
args: release --clean
7679
env:
7780
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
78-
GITHUB_SBOM_PATH: ${{ steps.sbom.outputs.fileName }}
81+
GITHUB_SBOM_PATH: /tmp/sbom.spdx.json

0 commit comments

Comments
 (0)