@@ -139,7 +139,7 @@ jobs:
139
139
continue-on-error : true
140
140
if : startsWith(github.ref, 'refs/tags/')
141
141
env :
142
- SBOM_SIGN_ALGORITHM : ${{ secrets.SBOM_SIGN_ALGORITHM }}
142
+ SBOM_SIGN_ALGORITHM : RS512
143
143
SBOM_SIGN_PRIVATE_KEY : ${{ github.workspace }}/private.key
144
144
- name : Attach cdx sbom to release
145
145
uses : softprops/action-gh-release@v2
@@ -198,7 +198,7 @@ jobs:
198
198
continue-on-error : true
199
199
if : startsWith(github.ref, 'refs/tags/')
200
200
env :
201
- SBOM_SIGN_ALGORITHM : ${{ secrets.SBOM_SIGN_ALGORITHM }}
201
+ SBOM_SIGN_ALGORITHM : RS512
202
202
SBOM_SIGN_PRIVATE_KEY : ${{ github.workspace }}/private.key
203
203
- name : Attach cdx secure sbom to release
204
204
uses : softprops/action-gh-release@v2
@@ -268,7 +268,7 @@ jobs:
268
268
continue-on-error : true
269
269
if : startsWith(github.ref, 'refs/tags/')
270
270
env :
271
- SBOM_SIGN_ALGORITHM : ${{ secrets.SBOM_SIGN_ALGORITHM }}
271
+ SBOM_SIGN_ALGORITHM : RS512
272
272
SBOM_SIGN_PRIVATE_KEY : ${{ github.workspace }}/private.key
273
273
- name : Attach cdx deno sbom to release
274
274
uses : softprops/action-gh-release@v2
@@ -384,7 +384,7 @@ jobs:
384
384
continue-on-error : true
385
385
if : startsWith(github.ref, 'refs/tags/')
386
386
env :
387
- SBOM_SIGN_ALGORITHM : ${{ secrets.SBOM_SIGN_ALGORITHM }}
387
+ SBOM_SIGN_ALGORITHM : RS512
388
388
SBOM_SIGN_PRIVATE_KEY : ${{ github.workspace }}/private.key
389
389
- name : Attach cdx bun sbom to release
390
390
uses : softprops/action-gh-release@v2
0 commit comments