We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 952833c commit 928ee95Copy full SHA for 928ee95
.github/workflows/generate-sbom.yaml
@@ -83,7 +83,7 @@ jobs:
83
echo "METALK8S_VERSION=$VERSION" >> $GITHUB_ENV
84
85
- name: Generate sbom for extracted ISO
86
- uses: scality/sbom@v2.1.0
+ uses: scality/sbom@v2
87
with:
88
target: ${{ env.BASE_PATH }}/iso/metalk8s.iso
89
target_type: iso
@@ -94,6 +94,15 @@ jobs:
94
merge: true
95
merge_hierarchical: true
96
97
+ - name: Upload sbom to Dependency-Track
98
+ uses: scality/sbom-upload@v1
99
+ with:
100
+ url: ${{ vars.DEPENDENCY_TRACK_HOSTNAME }}
101
+ api-key: ${{ secrets.DEPENDENCYTRACK_APIKEY }}
102
+ hierarchy-input-dir: ${{ env.SBOM_PATH }}
103
+ generate-hierarchy: true
104
+ hierarchy-upload: true
105
+
106
- name: Generate archive
107
shell: bash
108
run: |
0 commit comments