Skip to content

Authenticate SBOM uploads with PIA - #300

Open
lukpueh wants to merge 1 commit into
eclipse-jgit:masterfrom
lukpueh:sbom-upload-via-pia
Open

lukpueh wants to merge 1 commit into
eclipse-jgit:masterfrom
lukpueh:sbom-upload-via-pia

Conversation

@lukpueh

@lukpueh lukpueh commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Replace the actions/upload-artifact step and deprecated store-sbom-data reusable-workflow job with the upload-sbom composite action, which uploads the SBOM to DependencyTrack (sbom.eclipse.org) via PIA.

PIA authenticates the upload with OIDC, hence the added id-token: write permission, and resolves the DependencyTrack project from product-name/product-version, so the hard-coded parent project UUID is no longer needed.

More at https://eclipse-csi.github.io/security-handbook/sbom/howto.html#how-to-upload-an-sbom-to-dependencytrack

Replace the `actions/upload-artifact` step and deprecated `store-sbom-data`
reusable-workflow job with the `upload-sbom` composite action, which
uploads the SBOM to DependencyTrack (sbom.eclipse.org) via PIA.

PIA authenticates the upload with OIDC, hence the added `id-token: write`
permission, and resolves the DependencyTrack project from
product-name/product-version, so the hard-coded parent project UUID is no
longer needed.

More at https://eclipse-csi.github.io/security-handbook/sbom/howto.html#how-to-upload-an-sbom-to-dependencytrack

Assisted-by: Claude:claude-opus-5
Signed-off-by: Lukas Puehringer <lukas.puehringer@eclipse-foundation.org>
@msohn

msohn commented Oct 2, 2026

Copy link
Copy Markdown
Member

Thank you for contributing to JGit!

JGit uses GerritHub for code changes and review, therefore pull requests in this repository cannot be merged.

Please make sure you have read the section on contributing patches of the Contributor Guide.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants