Repository navigation
166 lines (135 loc) · 4.55 KB
/
Copy pathbuild.yml
File metadata and controls
166 lines (135 loc) · 4.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
name: Build
on:
push:
branches: [ "master", "ci" ]
tags:
- "v*"
pull_request:
branches: [ "master" ]
jobs:
build:
runs-on: windows-2025
timeout-minutes: 10
steps:
- uses: actions/checkout@v7
- name: Setup MSBuild
uses: microsoft/setup-msbuild@v3
- name: Setup NuGet
uses: NuGet/setup-nuget@v4
- name: Restore Packages
run: MSBuild.exe -p:Configuration="Release" -t:restore
- name: Build
run: MSBuild.exe -p:Configuration="Release"
- name: Export binaries
uses: actions/upload-artifact@v6
with:
name: PositionInterfaceClient.zip
path: ${{ github.workspace }}/bin/Release
# For some reason sbomify with cdxgen fails to generate the initial SBOM (although it works with other repos)
# Instead we generate it here like this
- name: Generate initial SBOM
uses: CycloneDX/gh-dotnet-generate-sbom@master
with:
path: ./PositionInterfaceClient.sln
json: true
github-bearer-token: ${{ secrets.GITHUB_TOKEN }}
- name: Export initial SBOM
uses: actions/upload-artifact@v6
with:
name: sbom_temp1.cdx.json
path: bom.json
sbom_pt1:
runs-on: ubuntu-latest
timeout-minutes: 10
needs: build
steps:
- uses: actions/checkout@v7
# Liest die Core-Version aus dem NSIS-Installer-Skript
- name: Get software version
run: |
VER_MAJOR=`grep -E -o "SWVersionMajor[[:blank:]]+=[[:blank:]][[:digit:]]+" MainWindow.xaml.cs | sed "s/[^0-9.]*//g"`
VER_MINOR=`grep -E -o "SWVersionMinor[[:blank:]]+=[[:blank:]][[:digit:]]+" MainWindow.xaml.cs | sed "s/[^0-9.]*//g"`
VER_PATCH=`grep -E -o "SWVersionPatch[[:blank:]]+=[[:blank:]][[:digit:]]+" MainWindow.xaml.cs | sed "s/[^0-9.]*//g"`
echo "Software version '$VER_MAJOR.$VER_MINOR.$VER_PATCH' detected"
echo "SW_VERSION=$VER_MAJOR.$VER_MINOR.$VER_PATCH" >> $GITHUB_ENV
- name: Import temporary SBOM
uses: actions/download-artifact@v8
with:
name: sbom_temp1.cdx.json
# SBOM erstellen
# Wie man die packages.lock.json bekommt: https://devblogs.microsoft.com/dotnet/enable-repeatable-package-restores-using-a-lock-file/
- uses: sbomify/sbomify-action@master
env:
SBOM_FILE: bom.json
#LOCK_FILE: packages.lock.json
OUTPUT_FILE: sbom_temp2.cdx.json
COMPONENT_NAME: PositionInterfaceClient
COMPONENT_VERSION: ${{ env.SW_VERSION }}
# Produkt- und Firmeninfo werden aus sbomify.json geladen
AUGMENT: true
# Metadaten aus Paket-Registry hinzufügen
ENRICH: true
# Metadaten aus additional_packages.txt hinzufügen
#ADDITIONAL_PACKAGES_FILE: ${{ github.workspace }}/additional_packages.txt
UPLOAD: false
- name: Export incomplete SBOM
uses: actions/upload-artifact@v7
with:
name: sbom_temp2.cdx.json
path: sbom_temp2.cdx.json
archive: false
sbom_pt2:
runs-on: windows-2025
timeout-minutes: 10
needs: sbom_pt1
steps:
- uses: actions/checkout@v7
- name: Import temporary SBOM
uses: actions/download-artifact@v8
with:
name: sbom_temp2.cdx.json
- name: Import binaries
uses: actions/download-artifact@v8
with:
name: PositionInterfaceClient.zip
skip-decompress: true
- name: Final SBOM enrichment
uses: CommonplaceRobotics/Action_SBOM_Enrichment@v9
with:
database: .github/workflows/sbom_enrichment_db.json
sbom: sbom_temp2.cdx.json
sbom_out: sbom.cdx.json
msproj_file: PositionInterfaceClient.csproj
- name: Export SBOM
uses: actions/upload-artifact@v7
with:
path: sbom.cdx.json
archive: false
- name: Validate SBOM with company policies
uses: CommonplaceRobotics/Action_Validate_SBOM@v6
with:
sbom: sbom.cdx.json
release:
name: Publish GitHub Release
needs: sbom_pt2
runs-on: ubuntu-latest
if: startsWith(github.ref, 'refs/tags/')
permissions:
contents: write
steps:
- name: Import binaries
uses: actions/download-artifact@v8
with:
name: PositionInterfaceClient.zip
path: dist/
skip-decompress: true
- name: Import SBOM
uses: actions/download-artifact@v8
with:
name: sbom.cdx.json
path: dist/
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
files: dist/*
generate_release_notes: true