We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 54b3125 commit 8e666aeCopy full SHA for 8e666ae
.github/workflows/sca-integration-osv.yml
@@ -31,11 +31,12 @@ jobs:
31
- name: Run OSV Scanner
32
uses: docker://ghcr.io/google/osv-scanner-action:v2.2.1
33
with:
34
- args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages > osv-scanner.spdx.json || true
+# args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages > osv-scanner.spdx.json || true
35
+ args: scan image --archive alpine_3.17.0.tar --format cyclonedx-1-5 --all-packages > osv-scanner.cdx.json || true
36
37
- name: Upload SBOM as GitHub Artifact
38
uses: actions/upload-artifact@v4
39
40
name: osv-scanner-sbom-report
- path: osv-scanner.spdx.json
41
+ path: osv-scanner.cdx.json
42
retention-days: 20
0 commit comments