Skip to content

Commit

Permalink
Fix SBOM publishing
Browse files Browse the repository at this point in the history
  • Loading branch information
prodrigestivill committed Aug 14, 2024
1 parent 6db3445 commit 6e7f783
Showing 1 changed file with 2 additions and 4 deletions.
6 changes: 2 additions & 4 deletions .github/workflows/sbom.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,15 +13,13 @@ jobs:
uses: anchore/sbom-action/download-syft@v0

- name: Generate SBOM with Syft from latest AMD64 image
run: syft scan registry:${{ vars.DOCKERHUB_REPO }}:latest --platform linux/amd64 --select-catalogers "+sbom-cataloger" --output spdx-json=sbom.spdx.json
run: syft scan registry:${{ vars.DOCKERHUB_REPO }}:latest --platform linux/amd64 --select-catalogers "+sbom-cataloger" --output spdx-json=docker.spdx.json

- name: Upload SBOM artifact
uses: actions/upload-artifact@v4
with:
name: docker-sbom
path: sbom.spdx.json
path: docker.spdx.json

- name: Upload SBOM to GitHub dependency submission API
uses: advanced-security/[email protected]
with:
filePath: sbom.spdx.json

0 comments on commit 6e7f783

Please sign in to comment.