We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent d04f595 commit cc78e48Copy full SHA for cc78e48
.github/workflows/build.yaml
@@ -37,3 +37,21 @@ jobs:
37
sbom: true
38
push: true
39
40
+ - name: attest provenance
41
+ uses: actions/attest-build-provenance@v3
42
+ with:
43
+ subject-name: ${{ env.IMAGE }}
44
+ # https://github.com/docker/bake-action/issues/99
45
+ subject-digest: ${{ fromJSON(steps.bake.outputs.metadata).default['containerimage.digest'] }}
46
+ push-to-registry: true
47
+
48
+ - name: attest SBOM
49
+ uses: actions/attest-sbom@v3
50
+ id: attest
51
52
53
54
55
+ sbom-path: 'sbom.spdx.json'
56
57
0 commit comments