Skip to content

Conversation

@willdollman
Copy link
Contributor

@willdollman willdollman commented Oct 14, 2024

Add missing changelog entry for #1115.

Also improve the error message when an unsupported version is passed:

Unsupported version <=5.8.0:

> go run ./cmd/src sbom fetch -v 5.8.0 --internal --insecure-ignore-tlog
unsupported version 5.8.0: SBOMs are only available for Sourcegraph releases after 5.8.0

Supported version >5.8.0:

>  go run ./cmd/src sbom fetch -v 5.8.287 --internal --insecure-ignore-tlog
Fetching SBOMs and validating signatures for all 55 images in the Sourcegraph 5.8.287 release...

⚠️ WARNING: Transparency log verification is disabled, increasing the risk that SBOMs may have been tampered with.
️          This setting should only be used for testing or under explicit instruction from Sourcegraph.

✅ us-central1-docker.pkg.dev/sourcegraph-ci/rfc795-internal/appliance
✅ us-central1-docker.pkg.dev/sourcegraph-ci/rfc795-internal/batcheshelper
[...]

Test plan

  • Tested change locally
  • CI

@willdollman willdollman self-assigned this Oct 14, 2024
@willdollman willdollman marked this pull request as ready for review October 14, 2024 09:15
@willdollman willdollman requested a review from a team October 14, 2024 09:15
@willdollman willdollman merged commit 847a899 into main Oct 14, 2024
@willdollman willdollman deleted the will/sbom-changelog branch October 14, 2024 10:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants