Skip to content

Commit ad7cd02

Browse files
committed
Make Trivy generate and submit SPDX SBOM
1 parent 6b0a436 commit ad7cd02

1 file changed

Lines changed: 20 additions & 2 deletions

File tree

‎.github/workflows/basic.yml‎

Lines changed: 20 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,8 +58,8 @@ jobs:
5858
run: |
5959
sycl-ls --verbose
6060
61-
#- name: Check formatting
62-
# run: cargo fmt --all -- --check
61+
- name: Check formatting
62+
run: cargo fmt --all -- --check
6363

6464
- name: Check C++ formatting
6565
run: |
@@ -109,9 +109,27 @@ jobs:
109109
name: Trivy scan
110110
runs-on: ubuntu-latest
111111

112+
permissions:
113+
contents: write
114+
112115
steps:
113116
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
114117

118+
- name: Generate SPDX SBOM with Trivy
119+
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
120+
with:
121+
scan-type: fs
122+
scan-ref: .
123+
format: spdx-json
124+
output: sbom.spdx.json
125+
126+
- name: Submit SPDX SBOM to GitHub dependency graph
127+
# uncomment
128+
#if: github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
129+
uses: advanced-security/spdx-dependency-submission-action@b009efcf8b9d562a4569d2028c276522232e631f # v0.4.0
130+
with:
131+
filePath: sbom.spdx.json
132+
115133
- name: Scan repository with Trivy
116134
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
117135
with:

0 commit comments

Comments
 (0)