mirror of
https://github.com/FreeRTOS/FreeRTOS-Kernel.git
synced 2025-07-04 11:27:16 -04:00
Merge 4bc8d25cec
into 0ae0715ac9
This commit is contained in:
commit
e9a6719563
12
.github/workflows/auto-release.yml
vendored
12
.github/workflows/auto-release.yml
vendored
|
@ -94,6 +94,18 @@ jobs:
|
|||
repo_path: ./local_kernel
|
||||
source_path: ./
|
||||
|
||||
# 1. Install cosign tool
|
||||
- name: Install Cosign
|
||||
uses: sigstore/cosign-installer@v3.8.1
|
||||
|
||||
# 2. Sign the sbom.spdx file using cosign. Two files are produced: sbom.sig and sbom.crt, stored in the same directory as sbom.spdx
|
||||
- name: Attest SBOM
|
||||
working-directory: ./local_kernel
|
||||
run: |
|
||||
cosign sign-blob sbom.spdx --output-certificate='sbom.crt' --output-signature='sbom.sig' -y
|
||||
# The following is a sanity check. After signing, we verify the image to check that everything is OK
|
||||
cosign verify-blob --signature='sbom.sig' --certificate='sbom.crt' --certificate-identity-regexp=.* --certificate-oidc-issuer-regexp='https://github.com' ./sbom.spdx
|
||||
|
||||
- name: commit SBOM file
|
||||
env:
|
||||
VERSION_NUMBER: ${{ github.event.inputs.version_number }}
|
||||
|
|
Loading…
Reference in a new issue