Skip to content

Replace unpinned actions with pinned action #73

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Jan 28, 2025
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 13 additions & 13 deletions .github/workflows/phase_2_harbor.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,14 +51,14 @@ jobs:
harbor-${HARBOR_TAG}

- name: Upload Generated CycloneDX SBOM
uses: actions/upload-artifact@v4 # v4
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 # v4
with:
name: generated-harbor-sbom-cyclonedx
path: "/tmp/generated-harbor-sbom.cdx.json"
if-no-files-found: error

- name: Upload Generated SPDX SBOM
uses: actions/upload-artifact@v4 # v4
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 # v4
with:
name: generated-harbor-sbom-spdx
path: "/tmp/generated-harbor-sbom.spdx.json"
Expand All @@ -72,10 +72,10 @@ jobs:
needs: Generate
steps:

- uses: actions/checkout@v4 # v4
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 # v4

- name: Download all workflow run artifacts
uses: actions/download-artifact@v4 # v4
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 # v4

- name: Augment Stage - List Downloaded Artifacts
run: ls -lha
Expand Down Expand Up @@ -125,13 +125,13 @@ jobs:
augmented_harbor-sbom.cdx.json > /tmp/augmented_harbor-sbom.cdx.json

- name: Upload Augmented SPDX SBOM
uses: actions/upload-artifact@v4 # v4
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 # v4
with:
name: augmented-harbor-sbom-spdx
path: "/tmp/augmented_harbor-sbom.spdx.json"

- name: Upload Augmented CycloneDX SBOM
uses: actions/upload-artifact@v4 # v4
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 # v4
with:
name: augmented-harbor-sbom-cyclonedx
path: "/tmp/augmented_harbor-sbom.cdx.json"
Expand All @@ -141,15 +141,15 @@ jobs:
needs: Augment
steps:

- uses: actions/checkout@v4 # v4
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 # v4
- name: Enrich Download all workflow run artifacts
uses: actions/download-artifact@v4 # v4
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 # v4

- name: Enrich Stage - List Downloaded Artifacts
run: ls -lha

- name: Enrich Stage - Download all workflow run artifacts
uses: actions/download-artifact@v4 # v4
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4 # v4

- name: Install parlay
run: |
Expand All @@ -167,13 +167,13 @@ jobs:
augmented-harbor-sbom-spdx/augmented_harbor-sbom.spdx.json > /tmp/enriched_harbor-sbom.spdx.json

- name: Upload Enriched SPDX SBOM
uses: actions/upload-artifact@v4 # v4
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 # v4
with:
name: enriched-harbor-sbom-spdx
path: "/tmp/enriched_harbor-sbom.spdx.json"

- name: Upload Enriched CycloneDX SBOM
uses: actions/upload-artifact@v4 # v4
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 # v4
with:
name: enriched-harbor-sbom-cyclonedx
path: "/tmp/enriched_harbor-sbom.cdx.json"
Expand All @@ -184,13 +184,13 @@ jobs:
cp /tmp/enriched_harbor-sbom.cdx.json /tmp/final_harbor-sbom.cdx.json

- name: Upload Final SPDX SBOM
uses: actions/upload-artifact@v4 # v4
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 # v4
with:
name: final-harbor-sbom-spdx
path: "/tmp/final_harbor-sbom.spdx.json"

- name: Upload Final CycloneDX SBOM
uses: actions/upload-artifact@v4 # v4
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4 # v4
with:
name: final-harbor-sbom-cyclonedx
path: "/tmp/final_harbor-sbom.cdx.json"
Expand Down
Loading