8000 Add SBOMs generation for Windows artifacts by sethmlarson · Pull Request #100 · python/release-tools · GitHub
[go: up one dir, main page]

Skip to content

Add SBOMs generation for Windows artifacts #100

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 11 commits into from
Apr 10, 2024
Merged
Prev Previous commit
Next Next commit
Move SBOM steps to MSI and embed stages
  • Loading branch information
sethmlarson committed Apr 4, 2024
commit 1d23d2da532a389877b86a6c88ad5f29838bcb26
6 changes: 0 additions & 6 deletions windows-release/azure-pipelines.yml
Original file line number Diff line number Diff line change
Expand Up @@ -147,12 +147,6 @@ stages:
SigningCertificate: ${{ parameters.SigningCertificate }}
DoFreethreaded: ${{ parameters.DoFreethreaded }}

- stage: SBOM
displayName: Create SBOMs
dependsOn: Build
jobs:
- template: stage-sbom.yml

- stage: Layout
displayName: Generate layouts
dependsOn: Sign
Expand Down
23 changes: 23 additions & 0 deletions windows-release/msi-steps.yml
Original file line number Diff line number Diff line change
Expand Up @@ -114,3 +114,26 @@ steps:
- publish: '$(Build.ArtifactStagingDirectory)\msi'
artifact: msi
displayName: 'Publish MSI'

- powershell: >
$(Python)
"$(Build.SourcesDirectory)\sbom.py"
"--cpython-source-dir=$(Build.SourcesDirectory)"
$(gci -r "$(Build.ArtifactStagingDirectory)\msi\**\python-*.exe")
workingDirectory: $(Build.BinariesDirectory)
displayName: 'Create SBOMs for binaries'

- task: CopyFiles@2
displayName: 'Layout Artifact: sbom'
inputs:
sourceFolder: $(Build.ArtifactStagingDirectory)\msi
targetFolder: $(Build.ArtifactStagingDirectory)\sbom
flatten: true
contents: |
**\*.spdx.json

- task: PublishBuildArtifacts@1
displayName: 'Publish Artifact: sbom_msi_$(Name)'
inputs:
PathtoPublish: '$(Build.ArtifactStagingDirectory)\sbom'
ArtifactName: sbom_msi_$(Name)
23 changes: 23 additions & 0 deletions windows-release/stage-layout-embed.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,3 +55,26 @@ jobs:
inputs:
PathtoPublish: '$(Build.ArtifactStagingDirectory)\embed'
ArtifactName: embed

- powershell: >
$(Python)
"$(Build.SourcesDirectory)\sbom.py"
"--cpython-source-dir=$(Build.SourcesDirectory)"
"$(Build.ArtifactStagingDirectory)\embed\python-$(VersionText)-embed-$(Name).zip"
workingDirectory: $(Build.BinariesDirectory)
displayName: 'Create SBOMs for binaries'

- task: CopyFiles@2
displayName: 'Layout Artifact: sbom'
inputs:
sourceFolder: $(Build.ArtifactStagingDirectory)\embed
targetFolder: $(Build.ArtifactStagingDirectory)\sbom
flatten: true
contents: |
**\*.spdx.json

- task: PublishBuildArtifacts@1
displayName: 'Publish Artifact: sbom_embed_$(Name)'
inputs:
PathtoPublish: '$(Build.ArtifactStagingDirectory)\sbom'
ArtifactName: sbom_embed_$(Name)
53 changes: 0 additions & 53 deletions windows-release/stage-sbom.yml

This file was deleted.

0