Browse Source

CLDC-4473: upload sbom directly

pull/3313/head
Nat Dean-Lewis 2 days ago
parent
commit
d805c39dea
  1. 21
      .github/workflows/upload-sbom.yml

21
.github/workflows/upload-sbom.yml

@ -41,12 +41,15 @@ jobs:
- run: syft . -o cyclonedx-xml=bom.xml - run: syft . -o cyclonedx-xml=bom.xml
- uses: DependencyTrack/gh-upload-sbom@v3 - name: Upload SBOM to Dependency-Track
with: env:
serverhostname: api-deps.softwire.com DTRACK_API_KEY: ${{ secrets.DTRACK_API_KEY }}
apikey: ${{ secrets.DTRACK_API_KEY }} SBOM_VERSION: ${{ inputs.projectversion }}
autocreate: true run: |
projectname: CORE curl -sSf -X POST "https://api-deps.softwire.com/api/v1/bom" \
projectversion: ${{ inputs.projectversion }} -H "X-Api-Key: $DTRACK_API_KEY" \
parentname: Support -F "autoCreate=true" \
bomfilename: bom.xml -F "projectName=CORE" \
-F "projectVersion=$SBOM_VERSION" \
-F "parentName=Support" \
-F "bom=@bom.xml"

Loading…
Cancel
Save