chore(deps-dev): bump typescript-eslint from 8.70.0 to 8.70.1 (#749)
Bumps typescript-eslint from 8.70.0 to 8.70.1.
updated-dependencies:
- dependency-name: typescript-eslint dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-patch …
Signed-off-by: dependabot[bot] support@github.com Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9
京公网安备 11010802047560号
GitHub Action for SBOM Generation
A GitHub Action for creating a software bill of materials (SBOM) using Syft.
Basic Usage
By default, this action will execute a Syft scan in the workspace directory and upload a workflow artifact SBOM in SPDX format. It will also detect if being run during a GitHub release and upload the SBOM as a release asset.
Example Usage
Scan a container image
To scan a container image, use the
imageparameter:The image will be fetched using the Docker daemon if available, which will use any authentication available to the daemon.
If the Docker daemon is not available, the action will retrieve the image directly from the container registry.
It is also possible to directly connect to the container registry with the
registry-usernameandregistry-passwordparameters. This will always bypass the Docker daemon:Scan a specific directory
Use the
pathparameter, relative to the repository root:Scan a specific file
Use the
fileparameter, relative to the repository root:Publishing SBOMs with releases
The
sbom-actionwill detect being run during a GitHub release and automatically upload all SBOMs as release assets. However, it may be desirable to upload SBOMs generated with other tools or using Syft outside this action. To do this, use theanchore/sbom-action/publish-sbomsub-action and specify a regular expression with thesbom-artifact-matchparameter:Naming the SBOM output
By default, this action will upload an artifact named
<repo>-<job-name>[-<step-id|step-number>].<extension>, for example:Will create 3 artifacts:
You may need to name these artifacts differently, simply use the
artifact-nameparameter:Permissions
This action needs the following permissions, depending on how it is being used:
If attaching release assets, the
actions: readpermission is also required. This may be implicit for public repositories, but is likely to be necessary for private repositories.Configuration
anchore/sbom-action
The main SBOM action, responsible for generating SBOMs and uploading them as workflow artifacts and release assets.
pathfileandimage.filepathandimage.imagepathandfile. See Scan a container image for more information.registry-usernameregistry-passwordartifact-namesbom-<job>-<step-id>.spdx.jsonoutput-fileformatspdx,spdx-json,cyclonedx,cyclonedx-jsonspdx-jsondependency-snapshotfalseupload-artifacttrueupload-artifact-retentionupload-release-assetstruesyft-versiongithub-tokengithub.tokenconfiganchore/sbom-action/publish-sbom
A sub-action to upload multiple SBOMs to GitHub releases.
sbom-artifact-match.*\.spdx\.json$anchore/sbom-action/download-syft
A sub-action to download Syft.
syft-versionOutput parameters:
cmdcmdcan be referenced in a workflow like other output parameters:${{ steps.<step-id>.outputs.cmd }}Windows
This action is tested on Windows, and should work natively on Windows hosts without WSL. (Note that it previously required WSL, but should now be run natively on Windows.)
Diagnostics
This action makes extensive use of GitHub Action debug logging, which can be enabled as described here by setting a secret in your repository of
ACTIONS_STEP_DEBUGtotrue.