Skip to content

Commit 5f74ab2

Browse files
committed
Sign the generated BOMs
Signed-off-by: Prabhu Subramanian <[email protected]>
1 parent 1b39558 commit 5f74ab2

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

.github/workflows/image-build.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -88,10 +88,11 @@ jobs:
8888
labels: ${{ steps.cdxgen-metadata.outputs.labels }}
8989
- name: save private key to file
9090
run: |
91-
echo "$SBOM_SIGN_PRIVATE_KEY_DATA" | base64 -d > $GITHUB_WORKSPACE/private.key
92-
ls -lh $GITHUB_WORKSPACE/private.key
91+
echo "SBOM_SIGN_PRIVATE_KEY" > $GITHUB_WORKSPACE/private.key.b64
92+
echo "SBOM_SIGN_PRIVATE_KEY" | base64 -d > $GITHUB_WORKSPACE/private.key
93+
ls -lh $GITHUB_WORKSPACE/private.key $GITHUB_WORKSPACE/private.key.b64
9394
env:
94-
SBOM_SIGN_PRIVATE_KEY_DATA: ${{ secrets.SBOM_SIGN_PRIVATE_KEY }}
95+
SBOM_SIGN_PRIVATE_KEY: ${{ secrets.SBOM_SIGN_PRIVATE_KEY }}
9596
- name: Attach cdx sbom to base
9697
run: |
9798
corepack pnpm install --config.strict-dep-builds=true --package-import-method copy --frozen-lockfile

0 commit comments

Comments
 (0)