Skip to content

SSDLC workflow should use local files instead of published snap #793

Description

@james-garner-canonical

Tony made contributions to https://github.com/canonical/sbomber to allow it to work with local files instead of pulling the artifact to be scanned from the snap store. We should update our use of the workflow in this repo to take advantage of this. This is particularly useful for this project due to race conditions with publishing (though the current workflow avoids this problem), and allowing us to use the same code for the FIPS branch (since we don't need to pull a different artifact from the store, just use the local files on the branch).

Metadata

Metadata

Assignees

No one assigned

    Labels

    26.04An item we hope to do in the 26.04 cyclerainy daySmall items done in ~10% of each week's timesmall itemA small item, for some value of 'small'

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions