atsign-foundation / at_server

The software implementation of Atsign's core technology
https://docs.atsign.com
BSD 3-Clause "New" or "Revised" License
39 stars 13 forks source link

ci: Add jobs to copy SBOMs into promoted release #2021

Closed cpswan closed 2 weeks ago

cpswan commented 2 weeks ago

Progresses https://github.com/atsign-foundation/operations/issues/133

- What I did

Added jobs to copy SBOMs from the canary we're promoting and generate a SLSA attestation for them

- How I did it

Prototyped in my release_automation repo

- How to verify it

We will need to promote a canary

- Description for the changelog

ci: Add jobs to copy SBOMs into promoted release