From 208e6e60fc98e24aac53676c3b6e7861189f36f7 Mon Sep 17 00:00:00 2001 From: scito Date: Sat, 15 Mar 2025 10:18:17 +0100 Subject: [PATCH] ci: add support for SBOM generation in Docker CI workflow --- .github/workflows/ci_docker.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/ci_docker.yml b/.github/workflows/ci_docker.yml index 8976661..505cd67 100644 --- a/.github/workflows/ci_docker.yml +++ b/.github/workflows/ci_docker.yml @@ -96,6 +96,7 @@ jobs: ghcr.io/scito/extract_otp_secrets:latest-${{ matrix.PLATFORM_ARCH }} ghcr.io/scito/extract_otp_secrets:bookworm-${{ matrix.PLATFORM_ARCH }} provenance: true + sbom: true # build on feature branches, push only on master branch push: ${{ github.ref == 'refs/heads/master' && github.secret_source == 'Actions'}} @@ -218,6 +219,7 @@ jobs: ghcr.io/scito/extract_otp_secrets:only-txt-${{ matrix.PLATFORM_ARCH }} ghcr.io/scito/extract_otp_secrets:alpine-${{ matrix.PLATFORM_ARCH }} provenance: true + sbom: true # build on feature branches, push only on master branch push: ${{ github.ref == 'refs/heads/master' && github.secret_source == 'Actions'}} build-args: | @@ -346,6 +348,7 @@ jobs: docker.io/scit0/extract_otp_secrets:bullseye-${{ matrix.PLATFORM_ARCH }} ghcr.io/scito/extract_otp_secrets:bullseye-${{ matrix.PLATFORM_ARCH }} provenance: true + sbom: true push: ${{ github.secret_source == 'Actions' }} - name: Image digest