8000 Add SPDX SBOM files to python.org releases · python/release-tools@c94bd5e · GitHub
[go: up one dir, main page]

Skip to content

Commit c94bd5e

Browse files 8000
committed
Add SPDX SBOM files to python.org releases
1 parent 76e1f69 commit c94bd5e

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

add-to-pydotorg.py

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -188,6 +188,9 @@ def build_file_dict(release, rfile, rel_pk, file_desc, os_pk,
188188
# Upload Sigstore bundle
189189
if os.path.exists(ftp_root + "%s/%s.sigstore" % (base_version(release), rfile)):
190190
d["sigstore_bundle_file"] = download_root + '%s/%s.sigstore' % (base_version(release), rfile)
191+
# Upload SPDX SBOM file
192+
if os.path.exists(ftp_root + "%s/%s.spdx.json" % (base_version(release), rfile)):
193+
d["sbom_spdx2_file"] = download_root + '%s/%s.spdx.json' % (base_version(release), rfile)
191194

192195
return d
193196

@@ -197,7 +200,7 @@ def list_files(release):
197200
for rfile in os.listdir(path.join(ftp_root, reldir)):
198201
if not path.isfile(path.join(ftp_root, reldir, rfile)):
199202
continue
200-
if rfile.endswith(('.asc', '.sig', '.crt', '.sigstore')):
203+
if rfile.endswith(('.asc', '.sig', '.crt', '.sigstore', '.spdx.json')):
201204
continue
202205
for prefix in ('python', 'Python'):
203206
if rfile.startswith(prefix):

0 commit comments

Comments
 (0)
0