Skip to content

Commit bc232f9

Browse files
NRL-1928 Allow pipeline to auth with github to upload sbom to release
1 parent 6ad6925 commit bc232f9

File tree

1 file changed

+5
-10
lines changed

1 file changed

+5
-10
lines changed

.github/workflows/release.yml

Lines changed: 5 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
1-
name: Release
1+
name: Release Published
22
run-name: Release NRL ${{ github.event.release.name }}
33
permissions:
44
id-token: write
5-
contents: read
5+
contents: write
66
actions: write
77

88
env:
@@ -112,16 +112,11 @@ jobs:
112112
JQ
113113
jq -r -f sbom_to_summary.jq sbom.spdx.json >> "$GITHUB_STEP_SUMMARY"
114114
115-
# - name: Upload SBOM to release
116-
# run: |
117-
# gh release upload ${{ github.event.release.tag_name }} sbom.spdx.json
118-
# env:
119-
# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
120-
121-
- name: Upload SBOM to release but better
115+
- name: Upload SBOM to release
122116
if: ${{ github.event.release.tag_name }}
123117
uses: svenstaro/upload-release-action@v2
124118
with:
125119
file: sbom.spdx.json
126-
asset_name: sbom-${{ github.ref }}
120+
asset_name: sbom-${{ github.event.release.tag_name }}
127121
tag: ${{ github.ref }}
122+
repo_token: ${{ secrets.GITHUB_TOKEN }}

0 commit comments

Comments
 (0)