Skip to content

Commit ef199c1

Browse files
committed
DEBUG workflow
Signed-off-by: tdruez <[email protected]>
1 parent 244c850 commit ef199c1

File tree

1 file changed

+14
-2
lines changed

1 file changed

+14
-2
lines changed

.github/workflows/sca-integration-ort-package-file.yml

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -63,11 +63,23 @@ jobs:
6363
--report-formats CycloneDX,SpdxDocument
6464
6565
- name: DEBUG
66-
run: ls -la ${GITHUB_WORKSPACE}/ort-data
66+
run: ls -la ${GITHUB_WORKSPACE}/ort-data/results
6767

6868
- name: Upload SBOMs as GitHub Artifact
6969
uses: actions/upload-artifact@v4
7070
with:
7171
name: ort-report
72-
path: "${GITHUB_WORKSPACE}/ort-data/*"
72+
path: "${GITHUB_WORKSPACE}/ort-data/results"
7373
retention-days: 20
74+
75+
- name: Import SBOM into ScanCode.io
76+
uses: aboutcode-org/scancode-action@main
77+
with:
78+
pipelines: "load_sbom"
79+
inputs-path: "${GITHUB_WORKSPACE}/ort-data/results/bom.cyclonedx.json"
80+
scancodeio-repo-branch: "main"
81+
82+
- name: Verify SBOM Analysis Results in ScanCode.io
83+
shell: bash
84+
run: |
85+
scanpipe shell --command "from scanpipe.models import DiscoveredPackage, DiscoveredDependency; package_manager = DiscoveredPackage.objects; print(package_manager.count()); print(package_manager.vulnerable().count()); print(DiscoveredDependency.objects.count())"

0 commit comments

Comments
 (0)