From 1653091d713b864adca0f9827200c553b8d1c0f4 Mon Sep 17 00:00:00 2001 From: jkowall Date: Wed, 19 Oct 2022 08:38:05 -0400 Subject: [PATCH] Adding anchore for SBOM signing during release Signed-off-by: jkowall --- .github/workflows/ci-release.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/ci-release.yml b/.github/workflows/ci-release.yml index 4cbb64d9965..ab17c813c5d 100644 --- a/.github/workflows/ci-release.yml +++ b/.github/workflows/ci-release.yml @@ -69,3 +69,8 @@ jobs: env: DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} QUAY_TOKEN: ${{ secrets.QUAY_TOKEN }} + + - name: SBOM Generation + uses: anchore/sbom-action@v0 + with: + artifact-name: jaeger-SBOM.spdx.json