From 5ad8523210efa2094c5dadcc341a5c4aa89f1731 Mon Sep 17 00:00:00 2001 From: mescon <5875228+mescon@users.noreply.github.com> Date: Tue, 15 Sep 2026 12:31:46 +0200 Subject: [PATCH] ci(release): mark the generator's tag reference as deliberate for SonarCloud SonarCloud's pin-by-hash rule fails the quality gate on the SLSA generator line. The generator has to be referenced by tag, or slsa-verifier cannot verify its ref, so the line carries the marker that tells the rule the choice is deliberate, with the reason. --- .github/workflows/publish-release.yml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.github/workflows/publish-release.yml b/.github/workflows/publish-release.yml index db15316..95cfa05 100644 --- a/.github/workflows/publish-release.yml +++ b/.github/workflows/publish-release.yml @@ -708,8 +708,9 @@ jobs: contents: write # attaches the statement to the release # Referenced by tag, not by commit hash, on purpose: slsa-verifier can # only verify the generator's ref when it is a tag (the generator's - # README, "Referencing SLSA builders and generators"). - uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.1.0 + # README, "Referencing SLSA builders and generators"). The marker + # below tells SonarCloud's pin-by-hash rule that this one is deliberate. + uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.1.0 # NOSONAR the SLSA generator must be referenced by tag with: base64-subjects: ${{ needs.hashes.outputs.hashes }} provenance-name: release-assets.intoto.jsonl