From ba8e3f9bc5c7e98bcfeefa6f034b3de20f3c9b95 Mon Sep 17 00:00:00 2001 From: CrazyMax Date: Thu, 15 Dec 2022 14:08:35 +0100 Subject: [PATCH] ci: generate provenance and sbom for bin image Signed-off-by: CrazyMax --- .github/workflows/build.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index d18ea5acf67..0166bc02f4f 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -163,6 +163,8 @@ jobs: set: | *.cache-from=type=gha,scope=bin-image *.cache-to=type=gha,scope=bin-image,mode=max + *.attest=type=sbom + *.attest=type=provenance,mode=max,builder-id=https://github.com/${{ env.GITHUB_REPOSITORY }}/actions/runs/${{ env.GITHUB_RUN_ID }} release: runs-on: ubuntu-latest