Skip to content

Commit 4d24864

Browse files
committed
Merge branch 'improvement/upload_to_dependencytrack' into tmp/octopus/w/132.0/improvement/upload_to_dependencytrack
2 parents 305764a + 928ee95 commit 4d24864

File tree

1 file changed

+10
-1
lines changed

1 file changed

+10
-1
lines changed

.github/workflows/generate-sbom.yaml

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,7 @@ jobs:
8383
echo "METALK8S_VERSION=$VERSION" >> $GITHUB_ENV
8484
8585
- name: Generate sbom for extracted ISO
86-
uses: scality/sbom@v2.1.0
86+
uses: scality/sbom@v2
8787
with:
8888
target: ${{ env.BASE_PATH }}/iso/metalk8s.iso
8989
target_type: iso
@@ -94,6 +94,15 @@ jobs:
9494
merge: true
9595
merge_hierarchical: true
9696

97+
- name: Upload sbom to Dependency-Track
98+
uses: scality/sbom-upload@v1
99+
with:
100+
url: ${{ vars.DEPENDENCY_TRACK_HOSTNAME }}
101+
api-key: ${{ secrets.DEPENDENCYTRACK_APIKEY }}
102+
hierarchy-input-dir: ${{ env.SBOM_PATH }}
103+
generate-hierarchy: true
104+
hierarchy-upload: true
105+
97106
- name: Generate archive
98107
shell: bash
99108
run: |

0 commit comments

Comments
 (0)