From c52be794b4fa99a30841451a7c230fd0b75f6e02 Mon Sep 17 00:00:00 2001 From: KatoVPN <267258587+katovpn@users.noreply.github.com> Date: Thu, 6 Aug 2026 14:43:40 +0300 Subject: [PATCH] release: emit attestable SBOM --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0b6fb6a..3e4c599 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -61,7 +61,7 @@ jobs: if ($executables.Count -ne 1) { throw "Expected one release executable, found $($executables.Count)." } $exe = $executables[0] $sbom = Join-Path $exe.DirectoryName "$($exe.BaseName).cdx.json" - cyclonedx-py requirements tools/nikki-router-setup/requirements.txt --output-reproducible --output-format JSON --output-file $sbom + cyclonedx-py requirements tools/nikki-router-setup/requirements.txt --output-format JSON --output-file $sbom if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } $hash = (Get-FileHash -LiteralPath $exe.FullName -Algorithm SHA256).Hash.ToLowerInvariant() "$hash $($exe.Name)" | Set-Content -LiteralPath (Join-Path $exe.DirectoryName 'SHA256SUMS.txt') -Encoding ascii