Skip to content

Commit 34aa387

Browse files
committed
add attestation actions
1 parent d04f595 commit 34aa387

File tree

1 file changed

+18
-0
lines changed

1 file changed

+18
-0
lines changed

.github/workflows/build.yaml

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,3 +37,21 @@ jobs:
3737
sbom: true
3838
push: true
3939

40+
- name: attest provenance
41+
uses: actions/attest-build-provenance@v3
42+
with:
43+
subject-name: ${{ env.IMAGE }}
44+
# https://github.com/docker/bake-action/issues/99
45+
subject-digest: ${{ fromJSON(steps.bake.outputs.metadata).default['containerimage.digest'] }}
46+
push-to-registry: true
47+
48+
- name: attest SBOM
49+
uses: actions/attest-sbom@v3
50+
id: attest
51+
with:
52+
subject-name: ${{ envIMAGE }}
53+
# https://github.com/docker/bake-action/issues/99
54+
subject-digest: ${{ fromJSON(steps.bake.outputs.metadata).default['containerimage.digest'] }}
55+
sbom-path: 'sbom.spdx.json'
56+
push-to-registry: true
57+

0 commit comments

Comments
 (0)