Skip to content

CI and SBOM updated #23

CI and SBOM updated

CI and SBOM updated #23

Workflow file for this run

name: Build
on:
push:
branches: [ "master", "ci" ]
tags:
- "v*"
pull_request:
branches: [ "master" ]
jobs:
build:
runs-on: windows-2025
timeout-minutes: 10
steps:
- uses: actions/checkout@v7
- name: Setup MSBuild
uses: microsoft/setup-msbuild@v3
- name: Setup NuGet
uses: NuGet/setup-nuget@v4
- name: Restore Packages
run: MSBuild.exe -p:Configuration="Release" -t:restore
- name: Build
run: MSBuild.exe -p:Configuration="Release"
- name: Export binaries
uses: actions/upload-artifact@v6
with:
name: PositionInterfaceClient.zip
path: ${{ github.workspace }}/bin/Release
# For some reason sbomify with cdxgen fails to generate the initial SBOM (although it works with other repos)
# Instead we generate it here like this
- name: Generate initial SBOM
uses: CycloneDX/gh-dotnet-generate-sbom@master
with:
path: ./PositionInterfaceClient.sln
json: true
github-bearer-token: ${{ secrets.GITHUB_TOKEN }}
- name: Export initial SBOM
uses: actions/upload-artifact@v6
with:
name: sbom_temp1.cdx.json
path: bom.json
sbom_pt1:
runs-on: ubuntu-latest
timeout-minutes: 10
needs: build
steps:
- uses: actions/checkout@v7
# Liest die Core-Version aus dem NSIS-Installer-Skript
- name: Get software version
run: |
VER_MAJOR=`grep -E -o "SWVersionMajor[[:blank:]]+=[[:blank:]][[:digit:]]+" MainWindow.xaml.cs | sed "s/[^0-9.]*//g"`
VER_MINOR=`grep -E -o "SWVersionMinor[[:blank:]]+=[[:blank:]][[:digit:]]+" MainWindow.xaml.cs | sed "s/[^0-9.]*//g"`
VER_PATCH=`grep -E -o "SWVersionPatch[[:blank:]]+=[[:blank:]][[:digit:]]+" MainWindow.xaml.cs | sed "s/[^0-9.]*//g"`
echo "Software version '$VER_MAJOR.$VER_MINOR.$VER_PATCH' detected"
echo "SW_VERSION=$VER_MAJOR.$VER_MINOR.$VER_PATCH" >> $GITHUB_ENV
- name: Import temporary SBOM
uses: actions/download-artifact@v8
with:
name: sbom_temp1.cdx.json
# SBOM erstellen
# Wie man die packages.lock.json bekommt: https://devblogs.microsoft.com/dotnet/enable-repeatable-package-restores-using-a-lock-file/
- uses: sbomify/sbomify-action@master
env:
SBOM_FILE: bom.json
#LOCK_FILE: packages.lock.json
OUTPUT_FILE: sbom_temp2.cdx.json
COMPONENT_NAME: PositionInterfaceClient
COMPONENT_VERSION: ${{ env.SW_VERSION }}
# Produkt- und Firmeninfo werden aus sbomify.json geladen
AUGMENT: true
# Metadaten aus Paket-Registry hinzufügen
ENRICH: true
# Metadaten aus additional_packages.txt hinzufügen
#ADDITIONAL_PACKAGES_FILE: ${{ github.workspace }}/additional_packages.txt
UPLOAD: false
- name: Export incomplete SBOM
uses: actions/upload-artifact@v7
with:
name: sbom_temp2.cdx.json
path: sbom_temp2.cdx.json
archive: false
sbom_pt2:
runs-on: windows-2025
timeout-minutes: 10
needs: sbom_pt1
steps:
- uses: actions/checkout@v7
- name: Import temporary SBOM
uses: actions/download-artifact@v8
with:
name: sbom_temp2.cdx.json
- name: Import binaries
uses: actions/download-artifact@v8
with:
name: PositionInterfaceClient.zip
skip-decompress: true
- name: Final SBOM enrichment
uses: CommonplaceRobotics/Action_SBOM_Enrichment@v9
with:
database: .github/workflows/sbom_enrichment_db.json
sbom: sbom_temp2.cdx.json
sbom_out: sbom.cdx.json
msproj_file: PositionInterfaceClient.csproj
- name: Export SBOM
uses: actions/upload-artifact@v7
with:
path: sbom.cdx.json
archive: false
- name: Validate SBOM with company policies
uses: CommonplaceRobotics/Action_Validate_SBOM@v6
with:
sbom: sbom.cdx.json
release:
name: Publish GitHub Release
needs: sbom_pt2
runs-on: ubuntu-latest
if: startsWith(github.ref, 'refs/tags/')
permissions:
contents: write
steps:
- name: Import binaries
uses: actions/download-artifact@v8
with:
name: PositionInterfaceClient.zip
path: dist/
skip-decompress: true
- name: Import SBOM
uses: actions/download-artifact@v8
with:
name: sbom.cdx.json
path: dist/
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
files: dist/*
generate_release_notes: true