relizaio/Rearm submit metadata

Submit Release metadata for a release on Rearm

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Dec 14, 2025
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: relizaio/rearm-add-release@d40cd001b969b385e0f5ad34e0f770d93df3a179 # 1.5.1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
rearm_api_idRearm Hub API IDyes
rearm_api_keyRearm Hub API KEYyes
image_full_nameFull name of the Docker image with registry prefixyes
image_digestSHA 256 digest of the image artifactyes
rearm_build_startBuild start timeyes
rearm_short_versionDocker and filesystem safe version from Rearm for this releaseyes
rearm_full_versionVersion obtained from Rearm for this releaseyes
rearm_build_statusBuild status - [complete | rejected]yes
rearm_api_urlRearm Hub API URLnohttps://demo.rearmhq.com
deliverable_typeType of artifact created by this release [CONTAINER, FILE]noCONTAINER
commit_listList of commitsno
rearm_component_idComponent UUID for this release if org-wide key is usedno
enable_sbomGenerates SBOM and stores it along with the artifactnofalse
source_code_sbom_typeGenerates SBOM based on source code analysis, possible values: npm, helm, custom, other, none. Use 'custom' to follow Dockerfile.sbom with expected output in /sbom/sbom.jsonnonone
registry_usernameUsername for image registryno
registry_passwordPassword for image registryno
registry_hostHost for image registryno
finalize_releaseFinalize the release after adding it (true/false)notrue
pathPath to the relative to root of the repo (default is '.')no.
send_sce_dataSends Source Code entry data along with the release, required for SCE SBOMsnotrue
last_commitLast registered commitno
enable_public_cosign_sigstoreSign deliverables and SBOMs using public sigstore via cosignnofalse
enable_codeqlEnable CodeQL analysisnofalse
codeql_languageLanguage to analyze with CodeQL, use 'custom' to follow Dockerfile.sarif with expected output in /sarif/results.sarifnonone
enable_securesbomEnable SecureSBOM signing of SBOMs by ShiftLeftCybernofalse
securesbom_pub_key_idPublic key id to sign with SecureSBOM by ShiftLeftCyberno
securesbom_hostSecureSBOM (by ShiftLeftCyber) hostno
securesbom_api_keySecureSBOM (by ShiftLeftCyber) API keyno

no outputs