Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions RELEASE.md
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,7 @@ To publish a stable release:
./tools/generate-sbom.sh /path/to/cortex
```
This generates SBOMs for the Go modules and all container images (cortex, query-tee, test-exporter, thanosconvert) and packages them into `dist/sbom.tar.gz`.
The Go modules SBOM is generated from a clean checkout of the release tag, so the tag must exist in your local repository. Untracked files in your working tree are not included.
1. Download the artifacts attached to the published release
```bash
curl -H "Authorization: Bearer <your GitHub API token>" -s https://api.github.com/repos/cortexproject/cortex/releases/tags/<release tag> \
Expand Down
10 changes: 9 additions & 1 deletion tools/generate-sbom.sh
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,20 @@ REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
RELEASE_TAG="v$(cat "${REPO_ROOT}/VERSION" | tr -d '[:space:]')"
CORTEX_REPO="${1:-$REPO_ROOT}"

# Scan a clean checkout of the release tag, not the working tree: bom includes
# every file under the directory, including untracked and gitignored ones.
# The checkout directory is named "cortex" because bom names the top-level
# package after it.
WORKTREE_PARENT="$(mktemp -d)"
trap 'git -C "$CORTEX_REPO" worktree remove --force "$WORKTREE_PARENT/cortex" >/dev/null 2>&1 || true; rm -rf "$WORKTREE_PARENT"' EXIT
git -C "$CORTEX_REPO" worktree add --detach "$WORKTREE_PARENT/cortex" "$RELEASE_TAG"

mkdir -p sbom

echo "Generating go-mod SBOM..."
bom generate -o sbom/go-mod.spdx \
-n https://github.com/cortexproject/cortex \
-d "$CORTEX_REPO"
-d "$WORKTREE_PARENT/cortex"

echo "Generating cortex container image SBOM..."
bom generate -o sbom/cortex-container-image.spdx \
Expand Down