diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 12ceb68a1..fcca211e4 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -238,3 +238,35 @@ jobs: push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} + + # This workflow runs on: branch and tag push, pull requests and manual dispatch. + # SBOMs are only wanted for two refs: `main`, uploaded as `@dev`, and + # `v*` release tags. Feature branches and pull requests are skipped. + maven-sbom: + name: Generate Maven SBOM + needs: build + if: github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v')) + permissions: + contents: read + id-token: write + uses: ./.github/workflows/generate-maven-sbom.yml + + npm-full-sbom: + name: Generate NPM Full SBOM + needs: build + if: github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v')) + permissions: + contents: read + packages: read + id-token: write + uses: ./.github/workflows/generate-npm-full-sbom.yml + + npm-runtime-sbom: + name: Generate NPM Runtime SBOM + needs: build + if: github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v')) + permissions: + contents: read + packages: read + id-token: write + uses: ./.github/workflows/generate-npm-runtime-sbom.yml diff --git a/.github/workflows/generate-maven-sbom.yml b/.github/workflows/generate-maven-sbom.yml index fd6e95921..3787abc34 100644 --- a/.github/workflows/generate-maven-sbom.yml +++ b/.github/workflows/generate-maven-sbom.yml @@ -1,9 +1,7 @@ name: Generate Maven SBOM on: - workflow_run: - workflows: [Continuous integration] - types: [completed] + workflow_call: workflow_dispatch: inputs: version: @@ -17,12 +15,8 @@ env: PRODUCT_PATH: "backend/application" PLUGIN_VERSION: "2.7.8" SBOM_TYPE: "makeAggregateBom" - WORKFLOW_CONCLUSION: ${{ github.event.workflow_run.conclusion }} - WORKFLOW_EVENT: ${{ github.event.workflow_run.event }} - WORKFLOW_HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }} GITHUB_REF: ${{ github.ref }} - INPUTS_VERSION: ${{ github.event.inputs.version }} - EVENT_NAME: ${{ github.event_name }} + INPUTS_VERSION: ${{ inputs.version }} permissions: contents: read @@ -31,16 +25,10 @@ jobs: generate-sbom: name: Generate SBOM for backend runs-on: ubuntu-latest - if: ${{ github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event != 'pull_request' && (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) }} - outputs: - project-version: ${{ steps.version.outputs.PROJECT_VERSION }} + permissions: + contents: read + id-token: write steps: - - name: Display metadata of workflow that has been completed before this one - run: | - echo "Run from workflow_run branch ${WORKFLOW_HEAD_BRANCH}" - echo "Run from workflow_run event ${WORKFLOW_EVENT}" - echo "Run on github.ref ${GITHUB_REF}" - - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -64,14 +52,13 @@ jobs: id: version shell: bash run: | - event="${EVENT_NAME}" - event_workflow_run_head_branch="${WORKFLOW_HEAD_BRANCH}" - ref="${GITHUB_REF}" - input="${INPUTS_VERSION}" - VERSION="$(jq -r '.metadata.component.version' < ./${{ env.PRODUCT_PATH }}/target/bom.json)" - if [[ "$event" == "workflow_run" ]] && [[ "$ref" == refs/heads/* ]] && [[ ! "$event_workflow_run_head_branch" =~ ^v ]]; then + # Only a v* release tag yields a clean version, anything else is a + # development snapshot. A called run builds GITHUB_REF, a manual run + # builds the ref it was given. + BUILT_REF="${INPUTS_VERSION:-$GITHUB_REF}" + if [[ ! "$BUILT_REF" =~ ^(refs/tags/)?v ]]; then VERSION="${VERSION}@dev" fi @@ -79,17 +66,8 @@ jobs: echo "Product version: $VERSION" - name: Upload sbom - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: eclipse-csi/workflows/upload-sbom@0c1c6cf5cb4dc624a86410274c71b27d6273385a # main with: - name: backend-sbom - path: ${{ env.PRODUCT_PATH }}/target/bom.json - - store-sbom-data: # stores sbom and metadata in a predefined format for otterdog to pick up - needs: ["generate-sbom"] - uses: eclipse-csi/workflows/.github/workflows/store-sbom-data.yml@main - with: - projectName: "SysON - Backend" - projectVersion: ${{ needs.generate-sbom.outputs.project-version }} - bomArtifact: "backend-sbom" - bomFilename: "bom.json" - parentProject: "75152c84-655b-4618-b23c-e5d3c3b562ae" + sbom-file: ${{ env.PRODUCT_PATH }}/target/bom.json + product-name: "SysON - Backend" + product-version: ${{ steps.version.outputs.PROJECT_VERSION }} diff --git a/.github/workflows/generate-npm-full-sbom.yml b/.github/workflows/generate-npm-full-sbom.yml index 464339cc0..a069e1e54 100644 --- a/.github/workflows/generate-npm-full-sbom.yml +++ b/.github/workflows/generate-npm-full-sbom.yml @@ -1,9 +1,7 @@ name: Generate NPM Full SBOM on: - workflow_run: - workflows: [Continuous integration] - types: [completed] + workflow_call: workflow_dispatch: inputs: version: @@ -15,12 +13,8 @@ env: NODE_VERSION: "24.20" REGISTRY_URL: "https://npm.pkg.github.com/" PRODUCT_PATH: "." - WORKFLOW_CONCLUSION: ${{ github.event.workflow_run.conclusion }} - WORKFLOW_EVENT: ${{ github.event.workflow_run.event }} - WORKFLOW_HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }} GITHUB_REF: ${{ github.ref }} - INPUTS_VERSION: ${{ github.event.inputs.version }} - EVENT_NAME: ${{ github.event_name }} + INPUTS_VERSION: ${{ inputs.version }} permissions: contents: read @@ -29,19 +23,12 @@ jobs: generate-sbom: name: Generate complete SBOM for frontend (including dev tools) runs-on: ubuntu-latest - if: ${{ github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event != 'pull_request' && (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) }} - outputs: - project-version: ${{ steps.version.outputs.PROJECT_VERSION }} permissions: + contents: read packages: read + id-token: write steps: - - name: Display metadata of workflow that has been completed before this one - run: | - echo "Run from workflow_run branch ${WORKFLOW_HEAD_BRANCH}" - echo "Run from workflow_run event ${WORKFLOW_EVENT}" - echo "Run on github.ref ${GITHUB_REF}" - - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -73,32 +60,22 @@ jobs: id: version shell: bash run: | - event="${EVENT_NAME}" - event_workflow_run_head_branch="${WORKFLOW_HEAD_BRANCH}" - ref="${GITHUB_REF}" - input="${INPUTS_VERSION}" - VERSION="$(jq -r '.metadata.component.version' < ./${{ env.PRODUCT_PATH }}/bom.json)" - if [[ "$event" == "workflow_run" ]] && [[ "$ref" == refs/heads/* ]] && [[ ! "$event_workflow_run_head_branch" =~ ^v ]]; then + # Only a v* release tag yields a clean version, anything else is a + # development snapshot. A called run builds GITHUB_REF, a manual run + # builds the ref it was given. + BUILT_REF="${INPUTS_VERSION:-$GITHUB_REF}" + if [[ ! "$BUILT_REF" =~ ^(refs/tags/)?v ]]; then VERSION="${VERSION}@dev" fi echo "PROJECT_VERSION=$VERSION" >> $GITHUB_OUTPUT echo "Product version: $VERSION" - - name: Upload SBOM as artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + - name: Upload SBOM + uses: eclipse-csi/workflows/upload-sbom@0c1c6cf5cb4dc624a86410274c71b27d6273385a # main with: - name: frontend-sbom - path: ${{ env.PRODUCT_PATH }}/bom.json - - store-sbom-data: # stores sbom and metadata in a predefined format for otterdog to pick up - needs: ["generate-sbom"] - uses: eclipse-csi/workflows/.github/workflows/store-sbom-data.yml@main - with: - projectName: "SysON - Frontend Full" - projectVersion: ${{ needs.generate-sbom.outputs.project-version }} - bomArtifact: "frontend-sbom" - bomFilename: "bom.json" - parentProject: "1b099ee7-62ee-48e1-986b-b7f0309dd344" + sbom-file: ${{ env.PRODUCT_PATH }}/bom.json + product-name: "SysON - Frontend Full" + product-version: ${{ steps.version.outputs.PROJECT_VERSION }} diff --git a/.github/workflows/generate-npm-runtime-sbom.yml b/.github/workflows/generate-npm-runtime-sbom.yml index 09622e750..0a85632a7 100644 --- a/.github/workflows/generate-npm-runtime-sbom.yml +++ b/.github/workflows/generate-npm-runtime-sbom.yml @@ -1,9 +1,7 @@ name: Generate NPM Runtime SBOM on: - workflow_run: - workflows: [Continuous integration] - types: [completed] + workflow_call: workflow_dispatch: inputs: version: @@ -15,12 +13,8 @@ env: NODE_VERSION: "24.20" REGISTRY_URL: "https://npm.pkg.github.com/" PRODUCT_PATH: "." - WORKFLOW_CONCLUSION: ${{ github.event.workflow_run.conclusion }} - WORKFLOW_EVENT: ${{ github.event.workflow_run.event }} - WORKFLOW_HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }} GITHUB_REF: ${{ github.ref }} - INPUTS_VERSION: ${{ github.event.inputs.version }} - EVENT_NAME: ${{ github.event_name }} + INPUTS_VERSION: ${{ inputs.version }} permissions: contents: read @@ -29,19 +23,12 @@ jobs: generate-sbom: name: Generate runtime SBOM for frontend (excluding dev tools) runs-on: ubuntu-latest - if: ${{ github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event != 'pull_request' && (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) }} - outputs: - project-version: ${{ steps.version.outputs.PROJECT_VERSION }} permissions: + contents: read packages: read + id-token: write steps: - - name: Display metadata of workflow that has been completed before this one - run: | - echo "Run from workflow_run branch ${WORKFLOW_HEAD_BRANCH}" - echo "Run from workflow_run event ${WORKFLOW_EVENT}" - echo "Run on github.ref ${GITHUB_REF}" - - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -73,32 +60,22 @@ jobs: id: version shell: bash run: | - event="${EVENT_NAME}" - event_workflow_run_head_branch="${WORKFLOW_HEAD_BRANCH}" - ref="${GITHUB_REF}" - input="${INPUTS_VERSION}" - VERSION="$(jq -r '.metadata.component.version' < ./${{ env.PRODUCT_PATH }}/bom.json)" - if [[ "$event" == "workflow_run" ]] && [[ "$ref" == refs/heads/* ]] && [[ ! "$event_workflow_run_head_branch" =~ ^v ]]; then + # Only a v* release tag yields a clean version, anything else is a + # development snapshot. A called run builds GITHUB_REF, a manual run + # builds the ref it was given. + BUILT_REF="${INPUTS_VERSION:-$GITHUB_REF}" + if [[ ! "$BUILT_REF" =~ ^(refs/tags/)?v ]]; then VERSION="${VERSION}@dev" fi echo "PROJECT_VERSION=$VERSION" >> $GITHUB_OUTPUT echo "Product version: $VERSION" - - name: Upload SBOM as artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + - name: Upload SBOM + uses: eclipse-csi/workflows/upload-sbom@0c1c6cf5cb4dc624a86410274c71b27d6273385a # main with: - name: frontend-sbom - path: ${{ env.PRODUCT_PATH }}/bom.json - - store-sbom-data: # stores sbom and metadata in a predefined format for otterdog to pick up - needs: ["generate-sbom"] - uses: eclipse-csi/workflows/.github/workflows/store-sbom-data.yml@main - with: - projectName: "SysON - Frontend Runtime" - projectVersion: ${{ needs.generate-sbom.outputs.project-version }} - bomArtifact: "frontend-sbom" - bomFilename: "bom.json" - parentProject: "1b099ee7-62ee-48e1-986b-b7f0309dd344" + sbom-file: ${{ env.PRODUCT_PATH }}/bom.json + product-name: "SysON - Frontend Runtime" + product-version: ${{ steps.version.outputs.PROJECT_VERSION }}