mirror of
https://github.com/pocket-id/pocket-id.git
synced 2026-09-21 18:39:05 +02:00
ci/cd: include SBOMs for binaries
This commit is contained in:
@@ -39,6 +39,11 @@ jobs:
|
||||
go-version-file: backend/go.mod
|
||||
cache-dependency-path: backend/go.sum
|
||||
|
||||
- name: Setup Syft
|
||||
uses: anchore/sbom-action/download-syft@v0.24.2
|
||||
with:
|
||||
syft-version: v1.52.0
|
||||
|
||||
- name: Set up Depot CLI
|
||||
uses: depot/setup-action@v1
|
||||
|
||||
|
||||
@@ -94,6 +94,23 @@ archives:
|
||||
checksum:
|
||||
name_template: checksums.txt
|
||||
|
||||
sboms:
|
||||
- id: binaries
|
||||
artifacts: binary
|
||||
disable: '{{ if index .Env "BUILD_NEXT" }}true{{ end }}'
|
||||
documents:
|
||||
- "pocket-id_{{ .Version }}_{{ .Os }}_{{ .Arch }}{{ targetVariant . }}.sbom.spdx.json"
|
||||
cmd: sh
|
||||
args:
|
||||
- ../scripts/development/generate-binary-sbom.sh
|
||||
- $artifact
|
||||
- $document
|
||||
- "pocket-id_{{ .Os }}_{{ .Arch }}{{ targetVariant . }}"
|
||||
- "{{ .Version }}"
|
||||
env:
|
||||
- SYFT_CHECK_FOR_APP_UPDATE=false
|
||||
- SYFT_CACHE_DIR=
|
||||
|
||||
docker_digest:
|
||||
name_template: digests.txt
|
||||
|
||||
|
||||
Executable
+22
@@ -0,0 +1,22 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -eu
|
||||
|
||||
artifact_path=$1
|
||||
document_path=$2
|
||||
source_name=$3
|
||||
source_version=$4
|
||||
frontend_sbom_path="../.tmp/frontend.cdx.json"
|
||||
|
||||
work_dir=$(mktemp -d "${TMPDIR:-/tmp}/pocket-id-binary-sbom.XXXXXX")
|
||||
trap 'rm -rf "$work_dir"' EXIT
|
||||
|
||||
cp "$artifact_path" "$work_dir/$(basename "$artifact_path")"
|
||||
cp "$frontend_sbom_path" "$work_dir/frontend.cdx.json"
|
||||
|
||||
syft "dir:$work_dir" \
|
||||
--select-catalogers "+sbom-cataloger" \
|
||||
--source-name "$source_name" \
|
||||
--source-version "$source_version" \
|
||||
--output "spdx-json=$document_path" \
|
||||
--enrich all
|
||||
Reference in New Issue
Block a user