Skip to content

Commit b93e411

Browse files
committed
DEBUG workflow
Signed-off-by: tdruez <[email protected]>
1 parent 7f42337 commit b93e411

File tree

1 file changed

+7
-8
lines changed

1 file changed

+7
-8
lines changed

.github/workflows/sca-integration-osv.yml

Lines changed: 7 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -21,13 +21,7 @@ env:
2121
jobs:
2222
generate-and-load-sbom:
2323
runs-on: ubuntu-24.04
24-
2524
steps:
26-
# - name: Docker
27-
# run: |
28-
# docker pull alpine:3.17.0
29-
# docker save alpine:3.17.0 > alpine_3.17.0.tar
30-
3125
- name: Install OSV-Scanner
3226
run: |
3327
curl -sLO https://github.com/google/osv-scanner/releases/latest/download/osv-scanner_linux_amd64
@@ -37,12 +31,12 @@ jobs:
3731
- name: Run OSV Scanner
3832
run: |
3933
osv-scanner scan --help
40-
osv-scanner scan image alpine:3.17.0 --all-packages --format spdx-2-3 --output sbom.spdx.json || true
34+
osv-scanner scan image ${{ env.IMAGE_REFERENCE }} --all-packages --format spdx-2-3 --output sbom.spdx.json || true
4135
4236
# - name: Run OSV Scanner
4337
# uses: docker://ghcr.io/google/osv-scanner-action:v2.2.1
4438
# with:
45-
# args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages > osv-scanner.spdx.json || true
39+
# args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages
4640
# args: scan image --archive alpine_3.17.0.tar --format json
4741

4842
- name: Upload SBOM as GitHub Artifact
@@ -51,3 +45,8 @@ jobs:
5145
name: osv-scanner-sbom-report
5246
path: sbom.spdx.json
5347
retention-days: 20
48+
49+
- name: Verify SBOM Analysis Results in ScanCode.io
50+
shell: bash
51+
run: |
52+
scanpipe shell --command "from scanpipe.models import DiscoveredPackage, DiscoveredDependency; package_manager = DiscoveredPackage.objects; print(package_manager.count()); print(package_manager.vulnerable().count()); print(DiscoveredDependency.objects.count())"

0 commit comments

Comments
 (0)