Skip to content

feat: publish cookbook OCI artifacts with SPDX - #87

Merged
damacus merged 3 commits into
mainfrom
feat/cookbook-oci
Sep 14, 2026
Merged

damacus merged 3 commits into
mainfrom
feat/cookbook-oci

Conversation

@damacus

@damacus damacus commented Sep 14, 2026

Copy link
Copy Markdown
Member

Summary

Cookbook maintainers can opt into publishing cookbook archives and SPDX SBOMs to ghcr.io/sous-chefs/cookbooks/<cookbook>:<version> alongside existing releases. OCI failures produce warnings and leave existing Supermarket publishing unaffected.

The separate reusable workflow packages the release tag using Cinc Workstation's cookbook loader and Supermarket staging code. It checks the metadata version, preserves file permissions and normalises archive timestamps. Anchore generates SPDX from the staged contents; ORAS pushes one cookbook payload layer and attaches the SPDX document. Workstation uses latest and third-party actions use major versions.

Verification

  • actionlint -shellcheck='' -pyflakes='' .github/workflows/release-cookbook.yml .github/workflows/publish-cookbook-oci.yml passed.
  • Extracted OCI shell steps passed shellcheck --shell bash -; git diff --check passed.
  • Packaged nginx 12.3.3 with Cinc Workstation, generated SPDX 2.3 covering 29 files, and pushed the cookbook and SPDX into a local registry with ORAS. Confirmed one payload layer and discovery of the SPDX referrer.

Follow-up

The nginx pilot will qualify actual GHCR publishing and public access. New GHCR packages need their visibility changed to public. This iteration publishes artifacts and SPDX only; signing, provenance and Cinc Supermarket registration are outside this change.

@damacus
damacus merged commit bc4eced into main Sep 14, 2026
6 checks passed
@damacus
damacus deleted the feat/cookbook-oci branch September 14, 2026 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant