Skip to content

security: add SBOM attestation to release - #65

Merged
rodri-oliveira-dev merged 1 commit into
mainfrom
feat/sbom-attestation-64
Sep 18, 2026
Merged

rodri-oliveira-dev merged 1 commit into
mainfrom
feat/sbom-attestation-64

Conversation

@rodri-oliveira-dev

@rodri-oliveira-dev rodri-oliveira-dev commented Sep 18, 2026 •

Copy link
Copy Markdown
Owner

Summary

Implements #64 by extending the existing release supply-chain controls with an SPDX SBOM and a signed SBOM attestation bound to the final NuGet package.

Changes

  • generates an SPDX JSON SBOM from the final .nupkg using anchore/sbom-action pinned to the immutable v0.24.0 commit;
  • validates the generated SBOM before accepting the release candidate;
  • includes the SBOM filename and SHA-256 in release-manifest.json;
  • includes the SBOM in SHA256SUMS and verifies it in every publishing job;
  • preserves the existing build-provenance attestations;
  • adds a dedicated GitHub SBOM attestation for the published .nupkg;
  • attaches the standalone SBOM to the GitHub Release;
  • documents provenance and SBOM verification with gh attestation verify in English and pt-BR.

Release integrity

The SBOM is generated once in build-and-pack, becomes part of the immutable release candidate, and is not regenerated by the publishing jobs. The same downloaded SBOM is hash-verified before publication and used by the attestation step.

Validation

The existing pull-request dry-run for .github/workflows/release.yml exercises package creation, SBOM generation/validation, release manifest generation, checksums and release-candidate upload without publishing a release.

Closes #64

Summary by CodeRabbit

  • Release Security

    • Releases now include an SPDX Software Bill of Materials (SBOM) describing package contents.
    • SBOM files are validated, checksummed, and included in release manifests and downloadable release assets.
    • NuGet packages and their SBOMs receive linked attestations to support provenance and integrity verification.
    • Publishing checks confirm that the exact validated artifacts are used throughout the release process.
  • Documentation

    • Added instructions for verifying build provenance and SBOM attestations with the GitHub CLI.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 1f14d6b9-9327-4f9d-9ebb-3d5e4aca9bb1

📥 Commits

Reviewing files that changed from the base of the PR and between d8e7734 and 4c8dce3.

📒 Files selected for processing (4)
  • .github/workflows/release.yml
  • docs/release-v1.0.0.md
  • docs/release-v1.0.0.pt-BR.md
  • scripts/release-candidate.cs

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The release workflow now generates and validates an SPDX JSON SBOM from the final NuGet package. The manifest and checksums record it. Publication jobs verify and attest it, upload it to GitHub Releases, and document verification commands.

Changes

Release SBOM

Layer / File(s) Summary
SBOM manifest contract
scripts/release-candidate.cs
Manifest creation and verification require the SBOM, record its filename and SHA-256 hash, and validate its checksum entry.
SBOM generation and release candidate wiring
.github/workflows/release.yml, docs/release-v1.0.0.md
The build job generates and validates an SPDX JSON SBOM from the final package and passes it into release candidate creation.
Publication, attestation, and verification
.github/workflows/release.yml, docs/release-v1.0.0.md, docs/release-v1.0.0.pt-BR.md
Publication jobs verify the SBOM, create artifact and package attestations, upload the SBOM, and document provenance and SBOM verification. The release gate requires the exact SBOM consumed by publication jobs.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant build-and-pack
  participant release-candidate.cs
  participant PublicationJobs
  participant GitHubRelease
  participant PackageAttestation
  build-and-pack->>release-candidate.cs: pass validated SPDX SBOM
  release-candidate.cs->>PublicationJobs: provide manifest and checksums
  PublicationJobs->>PublicationJobs: verify package and SBOM
  PublicationJobs->>PackageAttestation: attest package with SBOM
  PublicationJobs->>GitHubRelease: upload SBOM and release artifacts
Loading

Merge Risk: ⚪ Minimal · up to 4c8dc

The release workflow’s SBOM attestation is correctly linked to the release package, with no confirmed merge-blocking issue.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the SBOM changes, links issue #64, and describes validation. However, it omits the required Checklist section and does not confirm the repository-specific commands or checklis… Add the required Checklist section from the repository template. Mark each applicable item and explain any incomplete validation, including dotnet tool restore, locked restore, Release build, tests, changelog status, breaking-change status,…
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: adding SBOM attestation to the release process.
Linked Issues check ✅ Passed For #64, the release workflow generates an SPDX JSON SBOM from the final .nupkg, validates it, and carries the same file through the immutable release candidate. release-candidate.cs records and v…
Out of Scope Changes check ✅ Passed The changes remain within #64. They add SBOM generation, validation, integrity metadata, publication, attestation, and verification documentation. The release-candidate script changes support SBOM int…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Full details: Description check

Explanation

The description explains the SBOM changes, links issue #64, and describes validation. However, it omits the required Checklist section and does not confirm the repository-specific commands or checklist items.

Resolution

Add the required Checklist section from the repository template. Mark each applicable item and explain any incomplete validation, including dotnet tool restore, locked restore, Release build, tests, changelog status, breaking-change status, dependency status, and sensitive-information review.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@rodri-oliveira-dev
rodri-oliveira-dev merged commit 732ada7 into main Sep 18, 2026
11 checks passed
@rodri-oliveira-dev
rodri-oliveira-dev deleted the feat/sbom-attestation-64 branch September 18, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Adicionar SBOM attestation ao fluxo de release

1 participant