Skip to content

Generate release SBOMs #12818

Description

@DariuszPorowski

Parent: #11777

Implementation plan: PR 14 — SBOM generation

Design: GoReleaser Release Lifecycle

Implementation PR: Not yet created.

Scope

Enable GoReleaser's native syft integration for raw CLI binary and production image SBOMs. Publish SBOMs as additive release assets and document their format and discovery path without changing existing asset contracts.

Acceptance criteria

  • CLI and image SBOM assets are present and well-formed on one RC draft release.
  • Parity checks classify the SBOM files as intentional additions.
  • Consumer documentation identifies formats and locations.
  • The implementation PR is linked and merged.

Activity

  1. DariuszPorowski commented on Aug 28, 2026

    @DariuszPorowski
    MemberAuthor

    Implementation PR: #12869 (draft), submitted as the top layer of stack #12738 above #12828.

    The implementation and local validation are complete: the real GoReleaser snapshot produced seven valid SPDX CLI SBOMs with no extra checksum sidecars, and deterministic Buildx fixtures cover per-platform image attestations. Keep the PR draft until the full SBOM set is observed on one RC draft release.

  2. added a commit that references this issue on Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions