Skip to content

Commit 8e666ae

Browse files
committed
DEBUG workflow
Signed-off-by: tdruez <[email protected]>
1 parent 54b3125 commit 8e666ae

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

.github/workflows/sca-integration-osv.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,11 +31,12 @@ jobs:
3131
- name: Run OSV Scanner
3232
uses: docker://ghcr.io/google/osv-scanner-action:v2.2.1
3333
with:
34-
args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages > osv-scanner.spdx.json || true
34+
# args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages > osv-scanner.spdx.json || true
35+
args: scan image --archive alpine_3.17.0.tar --format cyclonedx-1-5 --all-packages > osv-scanner.cdx.json || true
3536

3637
- name: Upload SBOM as GitHub Artifact
3738
uses: actions/upload-artifact@v4
3839
with:
3940
name: osv-scanner-sbom-report
40-
path: osv-scanner.spdx.json
41+
path: osv-scanner.cdx.json
4142
retention-days: 20

0 commit comments

Comments
 (0)