Skip to content

Correct stale SBOM comment in build workflow - #449

Merged
btschwertfeger merged 1 commit into
masterfrom
fix-sbom-comment
Jul 30, 2026
Merged

Correct stale SBOM comment in build workflow#449
btschwertfeger merged 1 commit into
masterfrom
fix-sbom-comment

Conversation

@btschwertfeger

Copy link
Copy Markdown
Owner

PR #447 dropped the gh release upload step that attached sbom.cdx.json to the GitHub Release, since immutable releases make a release-time asset upload unworkable from a job triggered on release: created. The comment above the SBOM generation step still described that removed behavior.

The SBOM now reaches consumers only as the digest-bound attestation written by actions/attest-sbom, so the comment says that instead.

@btschwertfeger btschwertfeger added Documentation Improvements or additions to documentation CI/CD Related to workflows and package publishing labels Jul 30, 2026
@btschwertfeger btschwertfeger self-assigned this Jul 30, 2026
@btschwertfeger btschwertfeger added this to the Upcoming Release milestone Jul 30, 2026
@btschwertfeger
btschwertfeger enabled auto-merge (squash) July 30, 2026 06:37
@btschwertfeger
btschwertfeger merged commit ade9454 into master Jul 30, 2026
23 of 24 checks passed
@btschwertfeger
btschwertfeger deleted the fix-sbom-comment branch July 30, 2026 06:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI/CD Related to workflows and package publishing Documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant