-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Major - P3
-
Affects Version/s: None
-
Component/s: None
-
R&D Security
-
Fully Compatible
-
ALL
-
v8.0
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Overview
upload_sbom_via_silkbomb_if_changed fails on v8.0-staging (build variant upload-sbom-if-changed) because the "Write temporary AWS credentials to Silkbomb environment file" step still references a deleted script path.
Root cause
SERVER-129061's legacy-per-branch-SBOM-automation removal deleted evergreen/write_silkbomb_env.sh on this branch (replaced by evergreen/functions/security_reporting_scripts/write_aws_creds_to_silkbomb_env_file.sh, which other SBOM tasks on this branch already use successfully), but upload_sbom_via_silkbomb_if_changed in etc/evergreen_yml_components/tasks/misc_tasks.yml was never updated to match, so the task fails with exit code 127 before it can run silkbomb.
Tracked as BF-43346.
Fix
Point the credentials-writing step at evergreen/functions/security_reporting_scripts/write_aws_creds_to_silkbomb_env_file.sh and drop the now-unused SILKBOMB_ENV_FILE env override (that script always writes to workdir/silkbomb.env, matching CONTAINER_ENV_FILES already in the task).