Skip to content

Commit eadcfdc

Browse files
authored
BC-8631 generate source sbom when tagging (#18)
1 parent 1216253 commit eadcfdc

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

.github/workflows/tag.yml

+14
Original file line numberDiff line numberDiff line change
@@ -49,3 +49,17 @@ jobs:
4949
pull: true
5050
tags: ${{ steps.docker_meta_img_hub.outputs.tags }}
5151
labels: ${{ steps.docker_meta_img_hub.outputs.labels }}
52+
53+
create_release:
54+
runs-on: ubuntu-latest
55+
permissions:
56+
contents: write
57+
steps:
58+
- name: generate sbom via dependency-graph
59+
run: gh api repos/${{ github.repository }}/dependency-graph/sbom > dependencies.sbom.json
60+
env:
61+
GH_TOKEN: ${{ github.token }}
62+
- name: create release
63+
uses: softprops/action-gh-release@v2
64+
with:
65+
files: dependencies.sbom.json

0 commit comments

Comments
 (0)