Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,14 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

### Fixed
- **rust/generate-sbom** - The cargo-cyclonedx cache had a prefix
`restore-keys`, so asking for a new version restored the previous
version's binary and `cargo install` then failed with "binary
`cargo-cyclonedx` already exists in destination". The cache now matches
the exact version only, the install uses `--force`, and a new step fails
if the installed version differs from `cyclonedx-version`.

### Fixed
- **rust/generate-sbom** - The `package` input passed `--package`, which
cargo-cyclonedx 0.5.x rejects; it now resolves the package's manifest with
Expand Down
21 changes: 18 additions & 3 deletions rust/generate-sbom/action.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -62,16 +62,31 @@ runs:
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ~/.cargo/bin/cargo-cyclonedx
# Exact key only: a prefix restore-key would restore another
# version's binary, which is never the one requested.
key: ${{ runner.os }}-cargo-cyclonedx-${{ inputs.cyclonedx-version }}
restore-keys: |
${{ runner.os }}-cargo-cyclonedx-

- name: Install cargo-cyclonedx
if: steps.cache-cyclonedx.outputs.cache-hit != 'true'
shell: bash
env:
CYCLONEDX_VERSION: ${{ inputs.cyclonedx-version }}
run: cargo install cargo-cyclonedx --locked --version "${CYCLONEDX_VERSION}"
# --force replaces any binary already in ~/.cargo/bin (for example one
# restored by a broader cargo cache).
run: cargo install cargo-cyclonedx --locked --force --version "${CYCLONEDX_VERSION}"

- name: Verify cargo-cyclonedx version
shell: bash
env:
CYCLONEDX_VERSION: ${{ inputs.cyclonedx-version }}
run: |
set -euo pipefail
installed=$(cargo cyclonedx --version | awk '{print $NF}')
echo "cargo-cyclonedx ${installed}"
if [ "${installed}" != "${CYCLONEDX_VERSION}" ]; then
echo "Error: cargo-cyclonedx ${installed} is installed, ${CYCLONEDX_VERSION} was requested"
exit 1
fi

- name: Generate SBOM
shell: bash
Expand Down
Loading