core icon indicating copy to clipboard operation
core copied to clipboard

Update legacy-release_sbom-generator.yaml

Open rashik1144 opened this issue 1 year ago • 2 comments

The workflow will generate the SBOM for each release in the release branch instead of core-test-results.

rashik1144 avatar Aug 14 '24 05:08 rashik1144

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarQube

dotcms-sonarqube[bot] avatar Aug 14 '24 05:08 dotcms-sonarqube[bot]

My only concern is that we are adding the commit After the commit we fix the release version and publish to github, therefore anyone actually looking at the files in the release commit will not see the sbom. Of course there is a chicken-egg problem here as the workflow is triggered off the release generation so the only way I see of fixing this would be to modify the main release workflow to add the steps before the release commit is created. It probably would be better to have the sbom combined with the single release commit, but a commit before would also be fine. If @bryanboza is ok with this extra post release commit just to get the sbom in there in the short term, then I am ok with that. Otherwise to handle this before our release workflow refactor would be to modify the current release workflow to include the required steps rather than its own workflow as we currently have.

spbolton avatar Aug 15 '24 09:08 spbolton

This PR is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 7 days.

github-actions[bot] avatar Sep 23 '24 02:09 github-actions[bot]

This PR is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 7 days.

github-actions[bot] avatar Nov 01 '24 02:11 github-actions[bot]

This PR was closed because it has been stalled with no activity.

github-actions[bot] avatar Nov 12 '24 01:11 github-actions[bot]