From cfde639573ab3f7ac6da07a67b0d673996be4528 Mon Sep 17 00:00:00 2001 From: brian d foy Date: Wed, 10 Jul 2024 07:32:02 -0400 Subject: [PATCH] add attestation bundle to release --- .github/workflows/release.yml | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index c610535..aee094e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -97,9 +97,11 @@ jobs: cat Changes-latest id: extract - name: Generate artifact attestation + id: attestation uses: actions/attest-build-provenance@v1 with: - subject-path: "*.tar.gz" + subject-path: ${{ env.ASSET_NAME }} + subject-name: ${{ env.ASSET_NAME }} - name: upload uses: softprops/action-gh-release@v1 with: @@ -107,5 +109,7 @@ jobs: draft: false prerelease: false name: ${{ steps.version.outputs.name }} - files: "*.tar.gz" + files: | + ${{ env.ASSET_NAME }} + ${{ steps.attestation,outputs.bundle-path }} token: ${{ secrets.RELEASE_ACTION_TOKEN }}