Skip to content

Commit 2860501

Browse files
committed
Debug GitHub workflow for OWASP dep-scan
Signed-off-by: tdruez <[email protected]>
1 parent 52d5d6e commit 2860501

File tree

1 file changed

+13
-13
lines changed

1 file changed

+13
-13
lines changed

.github/workflows/sca-integration-depscan.yml

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
run: |
2626
docker pull ${{ env.IMAGE_REFERENCE }}
2727
docker save --output docker-image.tar ${{ env.IMAGE_REFERENCE }}
28-
chmod 644 docker-image.tar
28+
# chmod 644 docker-image.tar
2929

3030
- name: Install OWASP dep-scan
3131
run: |
@@ -38,8 +38,8 @@ jobs:
3838
--src docker-image.tar \
3939
--type docker \
4040
--explain \
41-
--reports-dir reports/ \
42-
--report-name depscan-sbom.cdx.json
41+
--reports-dir reports/
42+
# --report-name depscan-sbom.cdx.json
4343
env:
4444
SCAN_DEBUG_MODE: debug
4545

@@ -63,13 +63,13 @@ jobs:
6363
path: reports/
6464
retention-days: 20
6565

66-
# - name: Import SBOM into ScanCode.io
67-
# uses: aboutcode-org/scancode-action@main
68-
# with:
69-
# pipelines: "load_sbom"
70-
# inputs-path: "depscan-sbom.cdx.json"
71-
#
72-
# - name: Verify SBOM Analysis Results in ScanCode.io
73-
# shell: bash
74-
# run: |
75-
# scanpipe shell --command "from scanpipe.models import DiscoveredPackage, DiscoveredDependency; package_manager = DiscoveredPackage.objects; assert package_manager.count() > 340; assert package_manager.vulnerable().count() == 0; assert DiscoveredDependency.objects.count() == 0"
66+
- name: Import SBOM into ScanCode.io
67+
uses: aboutcode-org/scancode-action@main
68+
with:
69+
pipelines: "load_sbom"
70+
inputs-path: "reports/sbom-docker.json"
71+
72+
- name: Verify SBOM Analysis Results in ScanCode.io
73+
shell: bash
74+
run: |
75+
scanpipe shell --command "from scanpipe.models import DiscoveredPackage, DiscoveredDependency; package_manager = DiscoveredPackage.objects; assert package_manager.count() > 340; assert package_manager.vulnerable().count() == 0; assert DiscoveredDependency.objects.count() == 0"

0 commit comments

Comments
 (0)