Skip to content
This repository has been archived by the owner on Dec 21, 2023. It is now read-only.

ci: Generate SBOMs for all container images on release #9419

Merged
merged 1 commit into from
Jan 10, 2023
Merged

Conversation

mowies
Copy link
Member

@mowies mowies commented Jan 10, 2023

This PR

  • generate SBOMs with Syft for all Keptn container images when a release is done
  • SBOMs are attached to the release as separate *.spdx.json files

Fixes #7163

Signed-off-by: Moritz Wiesinger <moritz.wiesinger@dynatrace.com>
@sonarcloud
Copy link

sonarcloud bot commented Jan 10, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@thisthat
Copy link
Member

Can we manually attach the sbom to the release v1.0.0?

@mowies
Copy link
Member Author

mowies commented Jan 10, 2023

yes, i'll do it this week

@mowies mowies merged commit e774d26 into master Jan 10, 2023
@mowies mowies deleted the sboms branch January 10, 2023 11:20
@mowies
Copy link
Member Author

mowies commented Jan 10, 2023

Can we manually attach the sbom to the release v1.0.0?

@thisthat done

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Publish SBOM for Keptn artifacts/images
2 participants