Skip to content

merge: merge branch 'THU/upgrade_dependencies_PROD-14745' #4

merge: merge branch 'THU/upgrade_dependencies_PROD-14745'

merge: merge branch 'THU/upgrade_dependencies_PROD-14745' #4

name: Track Dependencies
on:
workflow_dispatch:
push:
branches:
- main
jobs:
dependency_track:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Enable Corepack
run: corepack enable
- name: Setup Node
uses: actions/setup-node@v5
with:
node-version: '24'
cache: 'yarn'
- name: Generate SBOM
run: yarn dlx -q @cyclonedx/yarn-plugin-cyclonedx -o sbom.json
- name: Upload CycloneDx bom to dependency track
uses: DependencyTrack/gh-upload-sbom@v3
with:
serverhostname: ${{ secrets.DEPENDENCY_TRACK_SERVER_HOSTNAME }}
apikey: ${{ secrets.DEPENDENCY_TRACK_API_KEY }}
project: 'd722d45d-8d16-4f4c-9d41-e8b8b58bb1ba'
bomfilename: 'sbom.json'