Skip to content

release: use exact SBOM path - #7

Merged
katovpn merged 1 commit into
mainfrom
codex/fix-sbom-attestation
Aug 6, 2026
Merged

katovpn merged 1 commit into
mainfrom
codex/fix-sbom-attestation

Conversation

@katovpn

@katovpn katovpn commented Aug 6, 2026

Copy link
Copy Markdown
Owner

Summary

  • pass the exact tag-derived CycloneDX path to the SBOM attestation action
  • keep the executable subject glob, which the action explicitly supports

Safety notes

  • workflow-only correction; no application or server behavior changes
  • the previous failed workflow published no release assets

Files changed

  • .github/workflows/release.yml

Verification performed

  • workflow YAML parsed and the tag template matches the generated versioned SBOM filename
  • prior retry completed build, checksum, SBOM generation, and provenance attestation

Approval required

  • merge before the final v0.4.3-preview retry

@katovpn
katovpn marked this pull request as ready for review August 6, 2026 11:39
@katovpn
katovpn merged commit 9e5615f into main Aug 6, 2026
1 check passed
@katovpn
katovpn deleted the codex/fix-sbom-attestation branch August 6, 2026 11:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant