We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents 7698297 + d9daeda commit de98bb3Copy full SHA for de98bb3
.github/workflows/sbom.yml
@@ -0,0 +1,28 @@
1
+name: Generate SBOM
2
+on:
3
+ release:
4
+ types: [published]
5
+
6
+jobs:
7
+ cyclone-dx:
8
+ runs-on: ubuntu-latest
9
+ steps:
10
+ - uses: actions/checkout@v4
11
+ - name: Generate SBOM
12
+ uses: CycloneDX/gh-action-node@v1
13
+ with:
14
+ output-format: "json"
15
+ output-file: "bom.json"
16
+ - name: Upload Artifact
17
+ uses: actions/upload-artifact@v3
18
19
+ name: sbom
20
+ path: bom.json
21
+ - name: Attach to Release
22
+ uses: actions/upload-release-asset@v1
23
+ env:
24
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
25
26
+ upload_url: ${{ github.event.release.upload_url }}
27
+ asset_path: ./bom.json
28
+ asset_name: "SBOM_${{ github.sha }}.json"
0 commit comments