From 7caba5a3fed21747233e24146ac1909809721750 Mon Sep 17 00:00:00 2001 From: Yang Chiu Date: Tue, 25 Jun 2024 09:13:08 +0800 Subject: [PATCH] ci: build and publish image with sbom attestation Signed-off-by: Yang Chiu --- .github/workflows/build.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 213e3f06..79eb1b40 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -80,6 +80,7 @@ jobs: platforms: linux/amd64,linux/arm64 tags: longhornio/backing-image-manager:${{ env.branch }}-head file: package/Dockerfile + sbom: true - name: docker-publish-with-tag if: ${{ startsWith(github.ref, 'refs/tags/') }} @@ -90,3 +91,4 @@ jobs: platforms: linux/amd64,linux/arm64 tags: longhornio/backing-image-manager:${{ github.ref_name }} file: package/Dockerfile + sbom: true