ci/cd: include SBOMs for binaries

This commit is contained in:
Elias Schneider
2026-09-20 15:13:11 +02:00
parent 5a1c6f0547
commit 8fe53ed42c
3 changed files with 44 additions and 0 deletions
+5
View File
@@ -39,6 +39,11 @@ jobs:
go-version-file: backend/go.mod
cache-dependency-path: backend/go.sum
- name: Setup Syft
uses: anchore/sbom-action/download-syft@v0.24.2
with:
syft-version: v1.52.0
- name: Set up Depot CLI
uses: depot/setup-action@v1
+17
View File
@@ -94,6 +94,23 @@ archives:
checksum:
name_template: checksums.txt
sboms:
- id: binaries
artifacts: binary
disable: '{{ if index .Env "BUILD_NEXT" }}true{{ end }}'
documents:
- "pocket-id_{{ .Version }}_{{ .Os }}_{{ .Arch }}{{ targetVariant . }}.sbom.spdx.json"
cmd: sh
args:
- ../scripts/development/generate-binary-sbom.sh
- $artifact
- $document
- "pocket-id_{{ .Os }}_{{ .Arch }}{{ targetVariant . }}"
- "{{ .Version }}"
env:
- SYFT_CHECK_FOR_APP_UPDATE=false
- SYFT_CACHE_DIR=
docker_digest:
name_template: digests.txt
+22
View File
@@ -0,0 +1,22 @@
#!/bin/sh
set -eu
artifact_path=$1
document_path=$2
source_name=$3
source_version=$4
frontend_sbom_path="../.tmp/frontend.cdx.json"
work_dir=$(mktemp -d "${TMPDIR:-/tmp}/pocket-id-binary-sbom.XXXXXX")
trap 'rm -rf "$work_dir"' EXIT
cp "$artifact_path" "$work_dir/$(basename "$artifact_path")"
cp "$frontend_sbom_path" "$work_dir/frontend.cdx.json"
syft "dir:$work_dir" \
--select-catalogers "+sbom-cataloger" \
--source-name "$source_name" \
--source-version "$source_version" \
--output "spdx-json=$document_path" \
--enrich all