Skip to content

fix: point SBOM generation at build/ not the zip - #23

Merged
jmgilman merged 1 commit into
masterfrom
session-007/fix-sbom-path
Apr 23, 2026
Merged

jmgilman merged 1 commit into
masterfrom
session-007/fix-sbom-path

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

anchore/sbom-action treats its `path` input as a directory (prepending `dir:` when invoking syft). Pointing at the zip produced `ERROR could not determine source` during the first release.yml run.

Fix: scan `build/` instead. That directory contains just the `bootstrap` Go binary, which is what the SBOM should describe. Syft resolves Go module deps directly from the binary's embedded build info.

The SBOM attestation's subject remains the zip (`dist/github-token-broker.zip`), correctly tying the SBOM predicate to the distributable artifact's digest.

Test plan

  • actionlint clean.
  • After merge, re-mint v1.0.0 tag at the new master HEAD; release.yml completes end-to-end.

🤖 Generated with Claude Code

anchore/sbom-action treats its `path` input as a directory (it prepends
`dir:` internally when invoking syft). Pointing it at
`dist/github-token-broker.zip` failed because syft tried to scan the
zip as if it were a directory and errored out.

Scan `build/` instead — it contains just the `bootstrap` Go binary,
which is exactly what we want the SBOM to describe. Syft resolves Go
module dependencies directly from the binary's embedded build info.

The subject of the SBOM attestation remains the zip
(`dist/github-token-broker.zip`), which is correct — the attestation
ties the SBOM predicate to the distributable artifact's digest.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@jmgilman
jmgilman merged commit 23c53f6 into master Apr 23, 2026
4 checks passed
@jmgilman
jmgilman deleted the session-007/fix-sbom-path branch April 23, 2026 04:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant