Skip to content

Add rpms and debs to provenance attestation and SBOM #3065

Open
@puerco

Description

@puerco

What would you like to be added:

We are now building the RPMs and debs as part of the release process. We should be recording these files in the provenance attestation on staging and accounting for them on the final SBOM after they're signed. We should also try to create an attestation of the OBS build if possible and record the packages there too.

Why is this needed:

Currently we don;t have a record of these files in our build metadata.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/release-engIssues or PRs related to the Release Engineering subprojectkind/featureCategorizes issue or PR as related to a new feature.needs-prioritysig/releaseCategorizes an issue or PR as relevant to SIG Release.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions