Skip to content

Commit f8f774b

Browse files
committed
Generate a SBOM as test data #1728
Signed-off-by: tdruez <[email protected]>
1 parent d0a7d56 commit f8f774b

File tree

2 files changed

+12
-11
lines changed

2 files changed

+12
-11
lines changed

.github/workflows/sca-integration-anchore.yml

Lines changed: 12 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,8 @@ permissions:
2222
contents: read
2323

2424
env:
25-
IMAGE_REFERENCE: "python:3.13.0-slim"
25+
IMAGE_REFERENCE: "alpine:3.17.0"
26+
# IMAGE_REFERENCE: "python:3.13.0-slim"
2627

2728
jobs:
2829
generate-and-load-sbom:
@@ -42,13 +43,13 @@ jobs:
4243
path: "anchore-grype-sbom.cdx.json"
4344
retention-days: 20
4445

45-
- name: Import SBOM into ScanCode.io
46-
uses: aboutcode-org/scancode-action@main
47-
with:
48-
pipelines: "load_sbom"
49-
inputs-path: "anchore-grype-sbom.cdx.json"
50-
51-
- name: Verify SBOM Analysis Results in ScanCode.io
52-
shell: bash
53-
run: |
54-
scanpipe shell --command "from scanpipe.models import DiscoveredPackage, DiscoveredDependency; package_manager = DiscoveredPackage.objects; assert package_manager.count() > 3200; assert package_manager.vulnerable().count() > 40; assert DiscoveredDependency.objects.count() > 220"
46+
# - name: Import SBOM into ScanCode.io
47+
# uses: aboutcode-org/scancode-action@main
48+
# with:
49+
# pipelines: "load_sbom"
50+
# inputs-path: "anchore-grype-sbom.cdx.json"
51+
#
52+
# - name: Verify SBOM Analysis Results in ScanCode.io
53+
# shell: bash
54+
# run: |
55+
# scanpipe shell --command "from scanpipe.models import DiscoveredPackage, DiscoveredDependency; package_manager = DiscoveredPackage.objects; assert package_manager.count() > 3200; assert package_manager.vulnerable().count() > 40; assert DiscoveredDependency.objects.count() > 220"
File renamed without changes.

0 commit comments

Comments
 (0)