We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 98a4e36 commit 24b7981Copy full SHA for 24b7981
1 file changed
.github/workflows/quality-checks.yml
@@ -244,15 +244,15 @@ jobs:
244
scan-type: "fs"
245
scan-ref: "."
246
scanners: "vuln"
247
- format: "spdx-json"
248
- output: "sbom.spdx.json"
+ format: "cyclonedx"
+ output: "sbom.cdx.json"
249
exit-code: "0"
250
trivy-config: trivy.yaml
251
- name: Upload sbom
252
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f
253
with:
254
- name: sbom.spdx.json
255
- path: sbom.spdx.json
+ name: sbom.cdx.json
+ path: sbom.cdx.json
256
257
- name: Check python vulnerabilities
258
if: ${{ steps.check_languages.outputs.uses_poetry == 'true' }}
0 commit comments