security: add SBOM attestation to release - #65
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe release workflow now generates and validates an SPDX JSON SBOM from the final NuGet package. The manifest and checksums record it. Publication jobs verify and attest it, upload it to GitHub Releases, and document verification commands. ChangesRelease SBOM
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant build-and-pack
participant release-candidate.cs
participant PublicationJobs
participant GitHubRelease
participant PackageAttestation
build-and-pack->>release-candidate.cs: pass validated SPDX SBOM
release-candidate.cs->>PublicationJobs: provide manifest and checksums
PublicationJobs->>PublicationJobs: verify package and SBOM
PublicationJobs->>PackageAttestation: attest package with SBOM
PublicationJobs->>GitHubRelease: upload SBOM and release artifacts
Merge Risk: ⚪ Minimal · up to The release workflow’s SBOM attestation is correctly linked to the release package, with no confirmed merge-blocking issue. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Description checkExplanation The description explains the SBOM changes, links issue Resolution Add the required Checklist section from the repository template. Mark each applicable item and explain any incomplete validation, including dotnet tool restore, locked restore, Release build, tests, changelog status, breaking-change status, dependency status, and sensitive-information review.
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Summary
Implements #64 by extending the existing release supply-chain controls with an SPDX SBOM and a signed SBOM attestation bound to the final NuGet package.
Changes
.nupkgusinganchore/sbom-actionpinned to the immutable v0.24.0 commit;release-manifest.json;SHA256SUMSand verifies it in every publishing job;.nupkg;gh attestation verifyin English and pt-BR.Release integrity
The SBOM is generated once in
build-and-pack, becomes part of the immutable release candidate, and is not regenerated by the publishing jobs. The same downloaded SBOM is hash-verified before publication and used by the attestation step.Validation
The existing pull-request dry-run for
.github/workflows/release.ymlexercises package creation, SBOM generation/validation, release manifest generation, checksums and release-candidate upload without publishing a release.Closes #64
Summary by CodeRabbit
Release Security
Documentation