Skip to content

Bump anchore/sbom-action from 0.16.0 to 0.17.0 (#88) #37

Bump anchore/sbom-action from 0.16.0 to 0.17.0 (#88)

Bump anchore/sbom-action from 0.16.0 to 0.17.0 (#88) #37

Workflow file for this run

name: CI
on:
push:
branches:
- master
tags:
- "v[0-9]+.[0-9]+.[0-9]+*"
pull_request:
branches:
- master
permissions:
contents: read
jobs:
build:
name: Build
runs-on: ubuntu-22.04
permissions:
contents: write
id-token: write
steps:
- name: Checkout Repository
uses: actions/checkout@v4.1.6
with:
fetch-depth: 0
- name: Setup Golang Environment
uses: actions/setup-go@v5.0.1
with:
go-version: stable
- name: Download Syft
uses: anchore/sbom-action/download-syft@v0.17.0
if: github.ref_type == 'tag'
- name: Install Cosign
uses: sigstore/cosign-installer@v3.5.0
if: github.ref_type == 'tag'
- name: Build binary
uses: goreleaser/goreleaser-action@v6.0.0
with:
version: latest
args: ${{ github.ref_type == 'tag' && 'release' || 'build --snapshot' }} --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}