sbon
Some checks failed
ci/woodpecker/push/woodpecker Pipeline failed

This commit is contained in:
Wolfgang Hottgenroth 2025-02-03 17:14:11 +01:00
parent a5b981357d
commit 0356e9dcee
Signed by: wn
GPG Key ID: 18FDFA577A8871AD

View File

@ -14,28 +14,38 @@ steps:
when: when:
- event: [push, tag] - event: [push, tag]
scan: generate_sbom:
image: quay.io/wollud1969/woodpecker-helper:0.5.1 image: aquasec/trivy:latest
environment: environment:
TRIVY_TOKEN: TRIVY_TOKEN:
from_secret: trivy_token from_secret: trivy_token
TRIVY_URL: TRIVY_URL:
from_secret: trivy_url from_secret: trivy_url
args:
- "fs"
- "--server"
- "${TRIVY_URL}"
- "--token"
- "${TRIVY_TOKEN}"
- "--format"
- "cyclonedx"
- "--scanners"
- "license"
- "--output"
- "sbom.xml"
- "."
when:
- event: [push, tag]
upload_sbom:
image: quay.io/wollud1969/woodpecker-helper:0.5.1
environment:
DTRACK_API_KEY: DTRACK_API_KEY:
from_secret: dtrack_api_key from_secret: dtrack_api_key
DTRACK_API_URL: DTRACK_API_URL:
from_secret: dtrack_api_url from_secret: dtrack_api_url
commands: commands:
- HOME=/home/`id -nu` - cat sbom.xml
- |
trivy fs \
--server $TRIVY_URL \
--token $TRIVY_TOKEN \
--format cyclonedx \
--scanners license \
--output /tmp/sbom.xml \
.
- cat /tmp/sbom.xml
- | - |
curl -X "POST" \ curl -X "POST" \
-H "Content-Type: multipart/form-data" \ -H "Content-Type: multipart/form-data" \
@ -43,7 +53,7 @@ steps:
-F "autoCreate=true" \ -F "autoCreate=true" \
-F "projectName=$CI_REPO" \ -F "projectName=$CI_REPO" \
-F "projectVersion=$CI_COMMIT_SHA" \ -F "projectVersion=$CI_COMMIT_SHA" \
-F "bom=@/tmp/sbom.xml"\ -F "bom=@sbom.xml"\
"$DTRACK_API_URL/api/v1/bom" "$DTRACK_API_URL/api/v1/bom"
when: when:
- event: [push, tag] - event: [push, tag]