From fe19380d6f227165318b8ddc6154529a692645d0 Mon Sep 17 00:00:00 2001 From: Abhimanyu Sharma Date: Thu, 29 Aug 2024 22:08:50 +0530 Subject: [PATCH] build: add support for SBOMs --- .github/workflows/goreleaser.yml | 2 ++ .goreleaser.yml | 3 +++ 2 files changed, 5 insertions(+) diff --git a/.github/workflows/goreleaser.yml b/.github/workflows/goreleaser.yml index 99ec8da..54a292b 100644 --- a/.github/workflows/goreleaser.yml +++ b/.github/workflows/goreleaser.yml @@ -15,6 +15,8 @@ jobs: uses: actions/setup-go@v5 with: go-version: 1.22 + - name: Install syft + uses: anchore/sbom-action/download-syft@61119d458adab75f756bc0b9e4bde25725f86a7a # v0.17.2 - name: Set up Snapcraft run: | sudo apt-get update diff --git a/.goreleaser.yml b/.goreleaser.yml index 5362ef0..3f8bd71 100644 --- a/.goreleaser.yml +++ b/.goreleaser.yml @@ -117,3 +117,6 @@ chocolateys: api_key: "{{ .Env.CHOCOLATEY_API_KEY }}" source_repo: "https://push.chocolatey.org/" skip_publish: true + +sboms: + - artifacts: archive