Skip to content

Commit

Permalink
run directly not as action
Browse files Browse the repository at this point in the history
Signed-off-by: Ramon Petgrave <[email protected]>
  • Loading branch information
ramonpetgrave64 committed Aug 9, 2024
1 parent 27bdcde commit 4089d6d
Showing 1 changed file with 32 additions and 6 deletions.
38 changes: 32 additions & 6 deletions .github/workflows/generator_generic_slsa3_alt.yml
Original file line number Diff line number Diff line change
Expand Up @@ -210,13 +210,39 @@ jobs:
echo "${UNTRUSTED_SUBJECTS}" > "${SUBJECTS_FILENAME}"
fi
- name: Generate slsa layout file
id: slsa-layout
uses: slsa-framework/slsa-github-generator/internal/builders/slsa-layout@ramonpetgrave64-internal-builder-sigstore-bundle
- name: Checkout the tool repo
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
with:
provenance-name: "${{ inputs.provenance-name }}"
base64-subjects-file: "${{ env.SUBJECTS_FILENAME }}"
slsa-layout-file: "${{ env.SLSA_LAYOUT_FILENAME }}"
repository: slsa-framework/slsa-github-generator
ref: 'ramonpetgrave64-internal-builder-sigstore-bundle'
path: __TOOL_CHECKOUT_DIR__

- shell: bash
env:
BASE64_SUBJECTS_FILE: ${{ env.SUBJECTS_FILENAME }}
PROVENANCE_NAME: ${{ inputs.provenance-name }}
OUTPUT_FILE: ${{ env.SLSA_LAYOUT_FILENAME }}
run: |

Check failure on line 225 in .github/workflows/generator_generic_slsa3_alt.yml

View workflow job for this annotation

GitHub Actions / shellcheck

shellcheck reported issue in this script: SC2086:info:9:23: Double quote to prevent globbing and word splitting ``` run: | ^~~~ ```
pwd
ls -lahR
DIR="$( pwd )"
(
cd __TOOL_CHECKOUT_DIR__/internal/builders/slsa-layout && \
ls -lahR && \
go run . \
--base64-subjects-file "$DIR"/"$BASE64_SUBJECTS_FILE" \
--provenance-name $PROVENANCE_NAME \
--output-file "$DIR"/"$OUTPUT_FILE"
)
echo "attestation-name=${PROVENANCE_NAME}" >>"${GITHUB_OUTPUT}"
# - name: Generate slsa layout file
# id: slsa-layout
# uses: slsa-framework/slsa-github-generator/internal/builders/slsa-layout@ramonpetgrave64-internal-builder-sigstore-bundle
# with:
# provenance-name: "${{ inputs.provenance-name }}"
# base64-subjects-file: "${{ env.SUBJECTS_FILENAME }}"
# slsa-layout-file: "${{ env.SLSA_LAYOUT_FILENAME }}"

- name: Generate attestations
id: attestations
Expand Down

0 comments on commit 4089d6d

Please sign in to comment.