for signing w/ private Sigstore instance (#16)
Signed-off-by: Brian DeHamer <[email protected]>
This commit is contained in:
@@ -60,6 +60,8 @@ jobs:
|
|||||||
- name: Run attest-sbom
|
- name: Run attest-sbom
|
||||||
id: attest-sbom
|
id: attest-sbom
|
||||||
uses: ./
|
uses: ./
|
||||||
|
env:
|
||||||
|
INPUT_PRIVATE-SIGNING: 'true'
|
||||||
with:
|
with:
|
||||||
subject-digest: 'sha256:7d070f6b64d9bcc530fe99cc21eaaa4b3c364e0b2d367d7735671fa202a03b32'
|
subject-digest: 'sha256:7d070f6b64d9bcc530fe99cc21eaaa4b3c364e0b2d367d7735671fa202a03b32'
|
||||||
subject-name: 'subject'
|
subject-name: 'subject'
|
||||||
@@ -86,7 +88,10 @@ jobs:
|
|||||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
sbom-format: 'spdx'
|
sbom-format: 'spdx'
|
||||||
- name: Run attest-sbom with cyclonedx format
|
- name: Run attest-sbom with cyclonedx format
|
||||||
|
id: attest-sbom
|
||||||
uses: ./
|
uses: ./
|
||||||
|
env:
|
||||||
|
INPUT_PRIVATE-SIGNING: 'true'
|
||||||
with:
|
with:
|
||||||
subject-digest: 'sha256:7d070f6b64d9bcc530fe99cc21eaaa4b3c364e0b2d367d7735671fa202a03b32'
|
subject-digest: 'sha256:7d070f6b64d9bcc530fe99cc21eaaa4b3c364e0b2d367d7735671fa202a03b32'
|
||||||
subject-name: 'subject'
|
subject-name: 'subject'
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
# `actions/attest-sbom`
|
# `actions/attest-sbom`
|
||||||
|
|
||||||
Generate signed SBOM attestations for workflow artifacts. Internally powered by
|
Generate signed SBOM attestations for workflow artifacts. Internally powered by
|
||||||
the [@actions/attest-sbom][1] package.
|
the [@actions/attest][1] package.
|
||||||
|
|
||||||
Attestations bind some subject (a named artifact along with its digest) to a a
|
Attestations bind some subject (a named artifact along with its digest) to a a
|
||||||
Software Bill of Materials (SBOM) using the [in-toto][2] format. The action
|
Software Bill of Materials (SBOM) using the [in-toto][2] format. The action
|
||||||
|
|||||||
Reference in New Issue
Block a user