Skip to content

v7.0 Test

v7.0 Test #2

name: createSBOM.yml
on:
release:
types: [created]
jobs:
create-sbom:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v2
- name: Generate SBOM with Syft
uses: anchore/sbom-action@v0
with:
path: .
output-file: "${{ github.event.repository.name }}-sbom.cyclonedx.json"
format: "cyclonedx-json"
config: ".syft/config.yml"
- name: Scan SBOM with Grype
id: scan
uses: anchore/scan-action@v5
with:
sbom: "${{ github.event.repository.name }}-sbom.cyclonedx.json"
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: ${{ steps.scan.outputs.sarif }}