diff --git a/.github/workflows/docker-build.yml b/.github/workflows/docker-build.yml index 14ef357..9488048 100644 --- a/.github/workflows/docker-build.yml +++ b/.github/workflows/docker-build.yml @@ -58,12 +58,3 @@ jobs: tag_name: ${{ steps.changelog.outputs.tag }} name: ${{ steps.changelog.outputs.tag }} body: ${{ steps.changelog.outputs.clean_changelog }} - - - name: Syft SBOM - uses: anchore/sbom-action@v0 - id: sbom - if: ${{ steps.changelog.outputs.skipped == 'false' }} - with: - image: registry.dangerous.tech/dangeroustech/zerotierbridge:latest - registry-username: ${{ secrets.REGISTRY_USERNAME }} - registry-password: ${{ secrets.REGISTRY_PASSWORD }} diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml new file mode 100644 index 0000000..9e25f02 --- /dev/null +++ b/.github/workflows/sbom.yml @@ -0,0 +1,17 @@ +name: Generate SBOM + +on: + release: + types: [created] + +jobs: + GenerateSBOM: + runs-on: ubuntu-latest + steps: + - name: Generate SBOM + uses: anchore/sbom-action@v0 + id: sbom + with: + image: registry.dangerous.tech/dangeroustech/zerotierbridge:latest + registry-username: ${{ secrets.REGISTRY_USERNAME }} + registry-password: ${{ secrets.REGISTRY_PASSWORD }}