Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -238,3 +238,35 @@ jobs:
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}

# This workflow runs on: branch and tag push, pull requests and manual dispatch.
# SBOMs are only wanted for two refs: `main`, uploaded as `<version>@dev`, and
# `v*` release tags. Feature branches and pull requests are skipped.
maven-sbom:
name: Generate Maven SBOM
needs: build
if: github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v'))
permissions:
contents: read
id-token: write
uses: ./.github/workflows/generate-maven-sbom.yml

npm-full-sbom:
name: Generate NPM Full SBOM
needs: build
if: github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v'))
permissions:
contents: read
packages: read
id-token: write
uses: ./.github/workflows/generate-npm-full-sbom.yml

npm-runtime-sbom:
name: Generate NPM Runtime SBOM
needs: build
if: github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v'))
permissions:
contents: read
packages: read
id-token: write
uses: ./.github/workflows/generate-npm-runtime-sbom.yml
50 changes: 14 additions & 36 deletions .github/workflows/generate-maven-sbom.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,7 @@
name: Generate Maven SBOM

on:
workflow_run:
workflows: [Continuous integration]
types: [completed]
workflow_call:
workflow_dispatch:
inputs:
version:
Expand All @@ -17,12 +15,8 @@ env:
PRODUCT_PATH: "backend/application"
PLUGIN_VERSION: "2.7.8"
SBOM_TYPE: "makeAggregateBom"
WORKFLOW_CONCLUSION: ${{ github.event.workflow_run.conclusion }}
WORKFLOW_EVENT: ${{ github.event.workflow_run.event }}
WORKFLOW_HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }}
GITHUB_REF: ${{ github.ref }}
INPUTS_VERSION: ${{ github.event.inputs.version }}
EVENT_NAME: ${{ github.event_name }}
INPUTS_VERSION: ${{ inputs.version }}

permissions:
contents: read
Expand All @@ -31,16 +25,10 @@ jobs:
generate-sbom:
name: Generate SBOM for backend
runs-on: ubuntu-latest
if: ${{ github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event != 'pull_request' && (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) }}
outputs:
project-version: ${{ steps.version.outputs.PROJECT_VERSION }}
permissions:
contents: read
id-token: write
steps:
- name: Display metadata of workflow that has been completed before this one
run: |
echo "Run from workflow_run branch ${WORKFLOW_HEAD_BRANCH}"
echo "Run from workflow_run event ${WORKFLOW_EVENT}"
echo "Run on github.ref ${GITHUB_REF}"

- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
Expand All @@ -64,32 +52,22 @@ jobs:
id: version
shell: bash
run: |
event="${EVENT_NAME}"
event_workflow_run_head_branch="${WORKFLOW_HEAD_BRANCH}"
ref="${GITHUB_REF}"
input="${INPUTS_VERSION}"

VERSION="$(jq -r '.metadata.component.version' < ./${{ env.PRODUCT_PATH }}/target/bom.json)"

if [[ "$event" == "workflow_run" ]] && [[ "$ref" == refs/heads/* ]] && [[ ! "$event_workflow_run_head_branch" =~ ^v ]]; then
# Only a v* release tag yields a clean version, anything else is a
# development snapshot. A called run builds GITHUB_REF, a manual run
# builds the ref it was given.
BUILT_REF="${INPUTS_VERSION:-$GITHUB_REF}"
if [[ ! "$BUILT_REF" =~ ^(refs/tags/)?v ]]; then
VERSION="${VERSION}@dev"
fi

echo "PROJECT_VERSION=$VERSION" >> $GITHUB_OUTPUT
echo "Product version: $VERSION"

- name: Upload sbom
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
uses: eclipse-csi/workflows/upload-sbom@0c1c6cf5cb4dc624a86410274c71b27d6273385a # main
with:
name: backend-sbom
path: ${{ env.PRODUCT_PATH }}/target/bom.json

store-sbom-data: # stores sbom and metadata in a predefined format for otterdog to pick up
needs: ["generate-sbom"]
uses: eclipse-csi/workflows/.github/workflows/store-sbom-data.yml@main
with:
projectName: "SysON - Backend"
projectVersion: ${{ needs.generate-sbom.outputs.project-version }}
bomArtifact: "backend-sbom"
bomFilename: "bom.json"
parentProject: "75152c84-655b-4618-b23c-e5d3c3b562ae"
sbom-file: ${{ env.PRODUCT_PATH }}/target/bom.json
product-name: "SysON - Backend"
product-version: ${{ steps.version.outputs.PROJECT_VERSION }}
51 changes: 14 additions & 37 deletions .github/workflows/generate-npm-full-sbom.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,7 @@
name: Generate NPM Full SBOM

on:
workflow_run:
workflows: [Continuous integration]
types: [completed]
workflow_call:
workflow_dispatch:
inputs:
version:
Expand All @@ -15,12 +13,8 @@ env:
NODE_VERSION: "24.20"
REGISTRY_URL: "https://npm.pkg.github.com/"
PRODUCT_PATH: "."
WORKFLOW_CONCLUSION: ${{ github.event.workflow_run.conclusion }}
WORKFLOW_EVENT: ${{ github.event.workflow_run.event }}
WORKFLOW_HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }}
GITHUB_REF: ${{ github.ref }}
INPUTS_VERSION: ${{ github.event.inputs.version }}
EVENT_NAME: ${{ github.event_name }}
INPUTS_VERSION: ${{ inputs.version }}

permissions:
contents: read
Expand All @@ -29,19 +23,12 @@ jobs:
generate-sbom:
name: Generate complete SBOM for frontend (including dev tools)
runs-on: ubuntu-latest
if: ${{ github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event != 'pull_request' && (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) }}
outputs:
project-version: ${{ steps.version.outputs.PROJECT_VERSION }}
permissions:
contents: read
packages: read
id-token: write

steps:
- name: Display metadata of workflow that has been completed before this one
run: |
echo "Run from workflow_run branch ${WORKFLOW_HEAD_BRANCH}"
echo "Run from workflow_run event ${WORKFLOW_EVENT}"
echo "Run on github.ref ${GITHUB_REF}"

- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
Expand Down Expand Up @@ -73,32 +60,22 @@ jobs:
id: version
shell: bash
run: |
event="${EVENT_NAME}"
event_workflow_run_head_branch="${WORKFLOW_HEAD_BRANCH}"
ref="${GITHUB_REF}"
input="${INPUTS_VERSION}"

VERSION="$(jq -r '.metadata.component.version' < ./${{ env.PRODUCT_PATH }}/bom.json)"

if [[ "$event" == "workflow_run" ]] && [[ "$ref" == refs/heads/* ]] && [[ ! "$event_workflow_run_head_branch" =~ ^v ]]; then
# Only a v* release tag yields a clean version, anything else is a
# development snapshot. A called run builds GITHUB_REF, a manual run
# builds the ref it was given.
BUILT_REF="${INPUTS_VERSION:-$GITHUB_REF}"
if [[ ! "$BUILT_REF" =~ ^(refs/tags/)?v ]]; then
VERSION="${VERSION}@dev"
fi

echo "PROJECT_VERSION=$VERSION" >> $GITHUB_OUTPUT
echo "Product version: $VERSION"

- name: Upload SBOM as artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
- name: Upload SBOM
uses: eclipse-csi/workflows/upload-sbom@0c1c6cf5cb4dc624a86410274c71b27d6273385a # main
with:
name: frontend-sbom
path: ${{ env.PRODUCT_PATH }}/bom.json

store-sbom-data: # stores sbom and metadata in a predefined format for otterdog to pick up
needs: ["generate-sbom"]
uses: eclipse-csi/workflows/.github/workflows/store-sbom-data.yml@main
with:
projectName: "SysON - Frontend Full"
projectVersion: ${{ needs.generate-sbom.outputs.project-version }}
bomArtifact: "frontend-sbom"
bomFilename: "bom.json"
parentProject: "1b099ee7-62ee-48e1-986b-b7f0309dd344"
sbom-file: ${{ env.PRODUCT_PATH }}/bom.json
product-name: "SysON - Frontend Full"
product-version: ${{ steps.version.outputs.PROJECT_VERSION }}
51 changes: 14 additions & 37 deletions .github/workflows/generate-npm-runtime-sbom.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,7 @@
name: Generate NPM Runtime SBOM

on:
workflow_run:
workflows: [Continuous integration]
types: [completed]
workflow_call:
workflow_dispatch:
inputs:
version:
Expand All @@ -15,12 +13,8 @@ env:
NODE_VERSION: "24.20"
REGISTRY_URL: "https://npm.pkg.github.com/"
PRODUCT_PATH: "."
WORKFLOW_CONCLUSION: ${{ github.event.workflow_run.conclusion }}
WORKFLOW_EVENT: ${{ github.event.workflow_run.event }}
WORKFLOW_HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }}
GITHUB_REF: ${{ github.ref }}
INPUTS_VERSION: ${{ github.event.inputs.version }}
EVENT_NAME: ${{ github.event_name }}
INPUTS_VERSION: ${{ inputs.version }}

permissions:
contents: read
Expand All @@ -29,19 +23,12 @@ jobs:
generate-sbom:
name: Generate runtime SBOM for frontend (excluding dev tools)
runs-on: ubuntu-latest
if: ${{ github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event != 'pull_request' && (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) }}
outputs:
project-version: ${{ steps.version.outputs.PROJECT_VERSION }}
permissions:
contents: read
packages: read
id-token: write

steps:
- name: Display metadata of workflow that has been completed before this one
run: |
echo "Run from workflow_run branch ${WORKFLOW_HEAD_BRANCH}"
echo "Run from workflow_run event ${WORKFLOW_EVENT}"
echo "Run on github.ref ${GITHUB_REF}"

- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
Expand Down Expand Up @@ -73,32 +60,22 @@ jobs:
id: version
shell: bash
run: |
event="${EVENT_NAME}"
event_workflow_run_head_branch="${WORKFLOW_HEAD_BRANCH}"
ref="${GITHUB_REF}"
input="${INPUTS_VERSION}"

VERSION="$(jq -r '.metadata.component.version' < ./${{ env.PRODUCT_PATH }}/bom.json)"

if [[ "$event" == "workflow_run" ]] && [[ "$ref" == refs/heads/* ]] && [[ ! "$event_workflow_run_head_branch" =~ ^v ]]; then
# Only a v* release tag yields a clean version, anything else is a
# development snapshot. A called run builds GITHUB_REF, a manual run
# builds the ref it was given.
BUILT_REF="${INPUTS_VERSION:-$GITHUB_REF}"
if [[ ! "$BUILT_REF" =~ ^(refs/tags/)?v ]]; then
VERSION="${VERSION}@dev"
fi

echo "PROJECT_VERSION=$VERSION" >> $GITHUB_OUTPUT
echo "Product version: $VERSION"

- name: Upload SBOM as artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
- name: Upload SBOM
uses: eclipse-csi/workflows/upload-sbom@0c1c6cf5cb4dc624a86410274c71b27d6273385a # main
with:
name: frontend-sbom
path: ${{ env.PRODUCT_PATH }}/bom.json

store-sbom-data: # stores sbom and metadata in a predefined format for otterdog to pick up
needs: ["generate-sbom"]
uses: eclipse-csi/workflows/.github/workflows/store-sbom-data.yml@main
with:
projectName: "SysON - Frontend Runtime"
projectVersion: ${{ needs.generate-sbom.outputs.project-version }}
bomArtifact: "frontend-sbom"
bomFilename: "bom.json"
parentProject: "1b099ee7-62ee-48e1-986b-b7f0309dd344"
sbom-file: ${{ env.PRODUCT_PATH }}/bom.json
product-name: "SysON - Frontend Runtime"
product-version: ${{ steps.version.outputs.PROJECT_VERSION }}
Loading