Skip to content

Commit 2a8a76f

Browse files
committed
Add GH workflow to generate SBOM with Anchore Syft #1728
Signed-off-by: tdruez <[email protected]>
1 parent 29c82e4 commit 2a8a76f

File tree

1 file changed

+26
-0
lines changed

1 file changed

+26
-0
lines changed
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
name: Generate SBOM with Anchore (Syft and Grype) and load into ScanCode.io
2+
3+
on:
4+
workflow_dispatch:
5+
pull_request:
6+
push:
7+
branches:
8+
- main
9+
10+
permissions:
11+
contents: read
12+
13+
env:
14+
IMAGE_REFERENCE: "python:3.13.0-slim"
15+
16+
jobs:
17+
generate-and-load-sbom:
18+
runs-on: ubuntu-24.04
19+
steps:
20+
- name: Generate CycloneDX SBOM with Anchore Syft
21+
uses: anchore/sbom-action@v0
22+
with:
23+
image: ${{ env.IMAGE_REFERENCE }}
24+
format: cyclonedx-json
25+
output-file: "anchore-report.sbom.json"
26+
upload-artifact: true

0 commit comments

Comments
 (0)