@@ -134,37 +134,6 @@ jobs:
134
134
make release-plugins
135
135
make manifests IMAGE_TAG=${{ github.event.inputs.tag }}
136
136
137
- - name : Generate SBOM (spdx)
138
- id : spdx-builder
139
- env :
140
- # defines the spdx/spdx-sbom-generator version to use.
141
- SPDX_GEN_VERSION : v0.0.13
142
- # defines the sigs.k8s.io/bom version to use.
143
- SIGS_BOM_VERSION : v0.2.1
144
- # comma delimited list of project relative folders to inspect for package
145
- # managers (gomod, yarn, npm).
146
- PROJECT_FOLDERS : " .,./ui"
147
- # full qualified name of the docker image to be inspected
148
- DOCKER_IMAGE : quay.io/codefresh/argo-rollouts:${{ github.event.inputs.tag }}
149
-
150
- run : |
151
- yarn install --cwd ./ui
152
- go install github.com/spdx/spdx-sbom-generator/cmd/generator@$SPDX_GEN_VERSION
153
- go install sigs.k8s.io/bom/cmd/bom@$SIGS_BOM_VERSION
154
-
155
- # Generate SPDX for project dependencies analyzing package managers
156
- for folder in $(echo $PROJECT_FOLDERS | sed "s/,/ /g")
157
- do
158
- generator -p $folder -o /tmp
159
- done
160
-
161
- # Generate SPDX for binaries analyzing the docker image
162
- if [[ ! -z $DOCKER_IMAGE ]]; then
163
- bom generate -o /tmp/bom-docker-image.spdx -i $DOCKER_IMAGE
164
- fi
165
-
166
- cd /tmp && tar -zcf sbom.tar.gz *.spdx
167
-
168
137
- name : Draft release
169
138
uses : softprops/action-gh-release@v1
170
139
with :
0 commit comments