File tree Expand file tree Collapse file tree 1 file changed +7
-8
lines changed Expand file tree Collapse file tree 1 file changed +7
-8
lines changed Original file line number Diff line number Diff line change 2121jobs :
2222 generate-and-load-sbom :
2323 runs-on : ubuntu-24.04
24-
2524 steps :
26- # - name: Docker
27- # run: |
28- # docker pull alpine:3.17.0
29- # docker save alpine:3.17.0 > alpine_3.17.0.tar
30-
3125 - name : Install OSV-Scanner
3226 run : |
3327 curl -sLO https://github.com/google/osv-scanner/releases/latest/download/osv-scanner_linux_amd64
@@ -37,12 +31,12 @@ jobs:
3731 - name : Run OSV Scanner
3832 run : |
3933 osv-scanner scan --help
40- osv-scanner scan image alpine:3.17.0 --all-packages --format spdx-2-3 --output sbom.spdx.json || true
34+ osv-scanner scan image ${{ env.IMAGE_REFERENCE }} --all-packages --format spdx-2-3 --output sbom.spdx.json || true
4135
4236# - name: Run OSV Scanner
4337# uses: docker://ghcr.io/google/osv-scanner-action:v2.2.1
4438# with:
45- # args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages > osv-scanner.spdx.json || true
39+ # args: scan image --archive alpine_3.17.0.tar --format spdx-2-3 --all-packages
4640# args: scan image --archive alpine_3.17.0.tar --format json
4741
4842 - name : Upload SBOM as GitHub Artifact
5145 name : osv-scanner-sbom-report
5246 path : sbom.spdx.json
5347 retention-days : 20
48+
49+ - name : Verify SBOM Analysis Results in ScanCode.io
50+ shell : bash
51+ run : |
52+ scanpipe shell --command "from scanpipe.models import DiscoveredPackage, DiscoveredDependency; package_manager = DiscoveredPackage.objects; print(package_manager.count()); print(package_manager.vulnerable().count()); print(DiscoveredDependency.objects.count())"
You can’t perform that action at this time.
0 commit comments