Skip to content

ci: Add SPDX formatted SBOM to the release workflow - #1428

Merged
boranx merged 1 commit into
masterfrom
jalseth/add-sbom
Sep 25, 2026
Merged

boranx merged 1 commit into
masterfrom
jalseth/add-sbom

Conversation

@jalseth

@jalseth jalseth commented Sep 19, 2026

Copy link
Copy Markdown
Member

Fixes #1117.

Signed-off-by: James Alseth <james@jalseth.me>
@jalseth

jalseth commented Sep 19, 2026

Copy link
Copy Markdown
Member Author

Tested locally:

$ goreleaser release --snapshot --clean --skip=publish
...

$ ls -1 dist/*.sbom.json
dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Darwin_arm64.tar.gz.sbom.json
dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Darwin_x86_64.tar.gz.sbom.json
dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Linux_arm64.tar.gz.sbom.json
dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Linux_ppc64le.tar.gz.sbom.json
dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Linux_s390x.tar.gz.sbom.json
dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Linux_x86_64.tar.gz.sbom.json
dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Windows_arm64.zip.sbom.json
dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Windows_x86_64.zip.sbom.json

$ jq . dist/conftest_0.70.1-SNAPSHOT-efc5d9e_Linux_x86_64.tar.gz.sbom.json | head -n 80
{
  "spdxVersion": "SPDX-2.3",
  "dataLicense": "CC0-1.0",
  "SPDXID": "SPDXRef-DOCUMENT",
  "name": "conftest_0.70.1-SNAPSHOT-efc5d9e_Linux_x86_64.tar.gz",
  "documentNamespace": "https://anchore.com/syft/file/conftest_0.70.1-SNAPSHOT-efc5d9e_Linux_x86_64.tar.gz-fe5b1cdc-38a2-46de-a6a5-4a9f0702d310",
  "creationInfo": {
    "licenseListVersion": "3.28",
    "creators": [
      "Organization: Anchore, Inc",
      "Tool: syft-1.51.1"
    ],
    "created": "2026-09-19T18:55:36Z"
  },
  "packages": [
    {
      "name": "cel.dev/expr",
      "SPDXID": "SPDXRef-Package-go-module-cel.dev-expr-f11b291a7bbcce02",
      "versionInfo": "v0.25.2",
      "supplier": "NOASSERTION",
      "downloadLocation": "NOASSERTION",
      "filesAnalyzed": false,
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "2ba8f8e82f35857b5941fb97eb471559014125a84a484da07d16cdbafaf96c5b"
        }
      ],
      "sourceInfo": "acquired package info from go module information: conftest",
      "licenseConcluded": "Apache-2.0",
      "licenseDeclared": "NOASSERTION",
      "copyrightText": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE-MANAGER",
          "referenceType": "purl",
          "referenceLocator": "pkg:golang/cel.dev/expr@v0.25.2"
        }
      ]
    },
    {
      "name": "cloud.google.com/go",
      "SPDXID": "SPDXRef-Package-go-module-cloud.google.com-go-31780039309ae395",
      "versionInfo": "v0.123.0",
      "supplier": "NOASSERTION",
      "downloadLocation": "NOASSERTION",
      "filesAnalyzed": false,
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "d8d0142703d1e3babe137e6e689798a0d86e34433d90cf128e046075e3895121"
        }
      ],
      "sourceInfo": "acquired package info from go module information: conftest",
      "licenseConcluded": "Apache-2.0 AND BSD-3-Clause",
      "licenseDeclared": "NOASSERTION",
      "copyrightText": "NOASSERTION",
      "externalRefs": [
        {
          "referenceCategory": "PACKAGE-MANAGER",
          "referenceType": "purl",
          "referenceLocator": "pkg:golang/cloud.google.com/go@v0.123.0"
        }
      ]
    },
    {
      "name": "cloud.google.com/go/auth",
      "SPDXID": "SPDXRef-Package-go-module-cloud.google.com-go-auth-4fe0030f442656f6",
      "versionInfo": "v0.23.2",
      "supplier": "NOASSERTION",
      "downloadLocation": "NOASSERTION",
      "filesAnalyzed": false,
      "checksums": [
        {
          "algorithm": "SHA256",
          "checksumValue": "a71482a5f8a38b8d61a73a4f74c09fb445027b3a60a6a9a60dd62202308a5f1a"
        }
      ],

@jalseth
jalseth requested a review from boranx September 19, 2026 18:57

@boranx boranx left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One step closer to releases with SBOMs 🎉

@boranx
boranx merged commit 722d53f into master Sep 25, 2026
13 checks passed
@boranx
boranx deleted the jalseth/add-sbom branch September 25, 2026 08:07
jalseth pushed a commit that referenced this pull request Sep 26, 2026
Netlify migrated the docs site to the Ubuntu 24.04 (Noble) build image,
which installs toolchains with mise. mise verifies GitHub artifact
attestations on the python-build-standalone tarballs it downloads, and
CPython 3.8.20 predates attestation coverage, so the pinned runtime
cannot be installed:

  mise ERROR Failed to install core:python@3.8: No GitHub artifact
  attestations found for python@3.8.20

Every Netlify deploy since 2026-09-25 07:27 UTC has failed, including
the production builds for the merges of #1430, #1427 and #1428. The
last successful publish of conftest.dev was 2026-09-19, so the site is
missing all three.

Bump runtime.txt to 3.12 and bring the docs toolchain forward to match,
since mkdocs-material 4.6.3 (2020) does not install under Python 3.12.
No mkdocs.yml changes are needed; the codehilite extension still works
under Markdown 3.x.

Signed-off-by: boranx <boran.seref@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Produce a SBOM

2 participants