Skip to content

Commit 50799f2

Browse files
committed
DEBUG cdxgen
Signed-off-by: tdruez <tdruez@nexb.com>
1 parent c2ddc22 commit 50799f2

File tree

1 file changed

+11
-11
lines changed

1 file changed

+11
-11
lines changed

.github/workflows/sca-integration-cdxgen.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
run: npm install @cyclonedx/cdxgen
2828

2929
- name: Generate SBOM with CycloneDX cdxgen
30-
run: npx cdxgen ${{ env.IMAGE_REFERENCE }} --type docker -output cdxgen-sbom.cdx.json --json-pretty
30+
run: npx cdxgen ${{ env.IMAGE_REFERENCE }} -t universal -output cdxgen-sbom.cdx.json --spec-version 1.6 --json-pretty
3131

3232
- name: Upload SBOM as GitHub Artifact
3333
uses: actions/upload-artifact@v4
@@ -36,13 +36,13 @@ jobs:
3636
path: "cdxgen-sbom.cdx.json"
3737
retention-days: 20
3838

39-
# - name: Import SBOM into ScanCode.io
40-
# uses: aboutcode-org/scancode-action@main
41-
# with:
42-
# pipelines: "load_sbom"
43-
# inputs-path: "cdxgen-sbom.cdx.json"
44-
#
45-
# - name: Verify SBOM Analysis Results in ScanCode.io
46-
# shell: bash
47-
# run: |
48-
# scanpipe shell --command "from scanpipe.models import DiscoveredPackage, DiscoveredDependency; package_manager = DiscoveredPackage.objects; assert package_manager.count() > 3200; assert package_manager.vulnerable().count() > 40; assert DiscoveredDependency.objects.count() > 220"
39+
- name: Import SBOM into ScanCode.io
40+
uses: aboutcode-org/scancode-action@main
41+
with:
42+
pipelines: "load_sbom"
43+
inputs-path: "cdxgen-sbom.cdx.json"
44+
45+
- name: Verify SBOM Analysis Results in ScanCode.io
46+
shell: bash
47+
run: |
48+
scanpipe shell --command "from scanpipe.models import DiscoveredPackage; package_manager = DiscoveredPackage.objects; print(package_manager.count());"

0 commit comments

Comments
 (0)