chore(demo): add chainloop

Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev>
This commit is contained in:
Miguel Martinez Trivino 2023-10-10 12:27:03 +02:00
parent c9825f7f7f
commit fb7d7c646f
No known key found for this signature in database
GPG key ID: 2270AF851FCFC96B
2 changed files with 15 additions and 1 deletions

2
.chainloop.yml Normal file
View file

@ -0,0 +1,2 @@
# defines files to be added to the attestation
attestation: {}

View file

@ -36,7 +36,7 @@ jobs:
collect-metadata:
runs-on: ubuntu-latest
name: "Security and Compliance Checks"
name: Generate metadata
needs: build
steps:
- name: Download all workflow run artifacts
@ -57,3 +57,15 @@ jobs:
with:
name: metadata
path: metadata/*
# Send metadata to Chainloop
chainloop:
name: Chainloop
uses: chainloop-dev/labs/.github/workflows/chainloop.yml@a75dff2ef342a1e5c5e1ec5c42fb99f3d1bc03cb
needs: collect-metadata
# with:
# contract_revision: 3
secrets:
api_token: ${{ secrets.CHAINLOOP_ROBOT_ACCOUNT }}
signing_key: ${{ secrets.PRIVATE_KEY }}
signing_key_password: ${{ secrets.PRIVATE_KEY_PASSWORD }}