@@ -139,7 +139,7 @@ jobs:
139139 continue-on-error : true
140140 if : startsWith(github.ref, 'refs/tags/')
141141 env :
142- SBOM_SIGN_ALGORITHM : ${{ secrets.SBOM_SIGN_ALGORITHM }}
142+ SBOM_SIGN_ALGORITHM : RS512
143143 SBOM_SIGN_PRIVATE_KEY : ${{ github.workspace }}/private.key
144144 - name : Attach cdx sbom to release
145145 uses : softprops/action-gh-release@v2
@@ -198,7 +198,7 @@ jobs:
198198 continue-on-error : true
199199 if : startsWith(github.ref, 'refs/tags/')
200200 env :
201- SBOM_SIGN_ALGORITHM : ${{ secrets.SBOM_SIGN_ALGORITHM }}
201+ SBOM_SIGN_ALGORITHM : RS512
202202 SBOM_SIGN_PRIVATE_KEY : ${{ github.workspace }}/private.key
203203 - name : Attach cdx secure sbom to release
204204 uses : softprops/action-gh-release@v2
@@ -268,7 +268,7 @@ jobs:
268268 continue-on-error : true
269269 if : startsWith(github.ref, 'refs/tags/')
270270 env :
271- SBOM_SIGN_ALGORITHM : ${{ secrets.SBOM_SIGN_ALGORITHM }}
271+ SBOM_SIGN_ALGORITHM : RS512
272272 SBOM_SIGN_PRIVATE_KEY : ${{ github.workspace }}/private.key
273273 - name : Attach cdx deno sbom to release
274274 uses : softprops/action-gh-release@v2
@@ -384,7 +384,7 @@ jobs:
384384 continue-on-error : true
385385 if : startsWith(github.ref, 'refs/tags/')
386386 env :
387- SBOM_SIGN_ALGORITHM : ${{ secrets.SBOM_SIGN_ALGORITHM }}
387+ SBOM_SIGN_ALGORITHM : RS512
388388 SBOM_SIGN_PRIVATE_KEY : ${{ github.workspace }}/private.key
389389 - name : Attach cdx bun sbom to release
390390 uses : softprops/action-gh-release@v2
0 commit comments