Skip to content

ci(release): attach the CycloneDX SBOM to each GitHub Release - #160

Merged
susheem-k merged 1 commit into
mainfrom
ci/release-attach-sbom
Sep 30, 2026
Merged

susheem-k merged 1 commit into
mainfrom
ci/release-attach-sbom

Conversation

@susheem-k

Copy link
Copy Markdown
Collaborator

What

The release workflow now attaches a CycloneDX SBOM to every GitHub Release.

  • sbom.yml gains a workflow_call trigger, so release.yml reuses the exact steps that run on every PR (build wheel, clean venv, cyclonedx-py, schema validation).
  • release.yml: a new sbom job (contents: read only) runs first. The release job needs it, downloads the artifact, asserts the SBOM is for agent-tokenops at the version being released, and attaches agent-tokenops-<version>.cdx.json to the GitHub Release.
  • Failure mode: if the SBOM job or the check fails, nothing is tagged, released or uploaded to PyPI.
  • The file is kept out of dist/, so the PyPI upload only sees the wheel and sdist.
  • RELEASING.md updated.

Why a separate job

The cyclonedx tooling is installed from PyPI; it stays out of the job that holds contents: write.

Checked

  • zizmor offline: clean. One finding suppressed inline with a reason: self-repository suggests the $/ syntax for the reusable-workflow reference; ./ is the long-standing form and I could not exercise the newer one, because this workflow cannot run in a PR.
  • The verification snippet was run locally against the CI-produced SBOM: passes for 0.4.0, fails on a version mismatch.
  • Not exercised: the release workflow itself only runs on manual dispatch and publishes to PyPI, so the first real run is the test. The sbom job runs first, so a problem there stops before anything is published.

Not in this PR

Version bump / changelog for the release that will carry the first SBOM, SBOM attestation, licence-data fixes.

🤖 Generated with Claude Code

- sbom.yml gains a workflow_call trigger so release.yml reuses the exact steps
  that run on every PR.
- release.yml: a read-only `sbom` job runs first; the release job needs it,
  downloads the artifact, checks it is for this package and version, and attaches
  agent-tokenops-<version>.cdx.json to the GitHub Release. If the SBOM fails,
  nothing is tagged, released or uploaded. The file stays out of dist/ so PyPI
  only sees the wheel and sdist.
- Suppress zizmor's self-repository finding with a reason (see comment).
- RELEASING.md: document the new step.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@susheem-k
susheem-k merged commit 3fedda9 into main Sep 30, 2026
9 checks passed
@susheem-k susheem-k mentioned this pull request Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant