diff --git a/.github/workflows/releases.yml b/.github/workflows/releases.yml index 3980456..ab536df 100644 --- a/.github/workflows/releases.yml +++ b/.github/workflows/releases.yml @@ -61,6 +61,9 @@ jobs: if: startsWith(github.ref, 'refs/tags/') id: run-cargo-release run: cargo build --verbose --release && cargo test --verbose + - name: Upload Release Asset + if: startsWith(github.ref, 'refs/tags/') + run: gh release upload ${{github.event.release.tag_name}} target/release/skootrs # TODO: Don't make this hardcoded. - name: Generate hashes id: hash @@ -93,6 +96,9 @@ jobs: with: name: skootrs.spdx.json path: skootrs.spdx.json + - name: Push SBOM to release + if: startsWith(github.ref, 'refs/tags/') + run: gh release upload ${{github.event.release.tag_name}} skootrs.spdx.json provenance-bins: permissions: id-token: write