Skip to content

Commit 65de814

Browse files
committed
Debug OSV-Scanner action #1730
Signed-off-by: tdruez <[email protected]>
1 parent c9e2509 commit 65de814

File tree

1 file changed

+8
-1
lines changed

1 file changed

+8
-1
lines changed

.github/workflows/sca-integration-osv.yml

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,4 +31,11 @@ jobs:
3131
- name: Run OSV Scanner
3232
uses: docker://ghcr.io/google/osv-scanner-action:v2.2.1
3333
with:
34-
args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages
34+
args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages > osv-scanner.spdx.json
35+
36+
- name: Upload SBOM as GitHub Artifact
37+
uses: actions/upload-artifact@v4
38+
with:
39+
name: osv-scanner-sbom-report
40+
path: osv-scanner.spdx.json
41+
retention-days: 20

0 commit comments

Comments
 (0)