Author SHA1 Message Date
dependabot[bot] 0894abea43 build(deps): bump anchore/sbom-action from 0.24.0 to 0.24.2
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.24.0 to 0.24.2.
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)
- [Commits](https://github.com/anchore/sbom-action/compare/e22c389904149dbc22b58101806040fa8d37a610...3ad7283483fc7af8ff2b4ea19663c2d5ca935e26)

---
updated-dependencies:
- dependency-name: anchore/sbom-action
  dependency-version: 0.24.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
2026-09-29 06:28:32 +00:00
flyemoji 451016bebd ci(release): write the sboms straight into dist 2026-09-29 15:25:49 +09:00
+7 -7
View File
@@ -72,23 +72,23 @@ jobs:
run: deploy/build-release-artifacts.sh "${GITHUB_REF_NAME}" dist
# A CycloneDX SBOM per binary: the Go modules (and versions) linked into it, read
# from the build info the linker embeds.
- uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
# from the build info the linker embeds. Written after SHA256SUMS, so beside it in the
# release but outside it: that lists what bootstrap installs. Straight into dist/,
# because the action does not create a missing output directory.
- uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
file: dist/felis-linux-amd64
format: cyclonedx-json
output-file: sbom/felis-linux-amd64.cdx.json
output-file: dist/felis-linux-amd64.cdx.json
upload-artifact: false
upload-release-assets: false
- uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
- uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
file: dist/felis-linux-arm64
format: cyclonedx-json
output-file: sbom/felis-linux-arm64.cdx.json
output-file: dist/felis-linux-arm64.cdx.json
upload-artifact: false
upload-release-assets: false
# Outside SHA256SUMS, which lists what bootstrap installs; beside it in the release.
- run: mv sbom/*.cdx.json dist/
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with: