We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent c9e2509 commit 65de814Copy full SHA for 65de814
.github/workflows/sca-integration-osv.yml
@@ -31,4 +31,11 @@ jobs:
31
- name: Run OSV Scanner
32
uses: docker://ghcr.io/google/osv-scanner-action:v2.2.1
33
with:
34
- args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages
+ args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages > osv-scanner.spdx.json
35
+
36
+ - name: Upload SBOM as GitHub Artifact
37
+ uses: actions/upload-artifact@v4
38
+ with:
39
+ name: osv-scanner-sbom-report
40
+ path: osv-scanner.spdx.json
41
+ retention-days: 20
0 commit comments