parent
a5b981357d
commit
0356e9dcee
@ -14,28 +14,38 @@ steps:
|
|||||||
when:
|
when:
|
||||||
- event: [push, tag]
|
- event: [push, tag]
|
||||||
|
|
||||||
scan:
|
generate_sbom:
|
||||||
image: quay.io/wollud1969/woodpecker-helper:0.5.1
|
image: aquasec/trivy:latest
|
||||||
environment:
|
environment:
|
||||||
TRIVY_TOKEN:
|
TRIVY_TOKEN:
|
||||||
from_secret: trivy_token
|
from_secret: trivy_token
|
||||||
TRIVY_URL:
|
TRIVY_URL:
|
||||||
from_secret: trivy_url
|
from_secret: trivy_url
|
||||||
|
args:
|
||||||
|
- "fs"
|
||||||
|
- "--server"
|
||||||
|
- "${TRIVY_URL}"
|
||||||
|
- "--token"
|
||||||
|
- "${TRIVY_TOKEN}"
|
||||||
|
- "--format"
|
||||||
|
- "cyclonedx"
|
||||||
|
- "--scanners"
|
||||||
|
- "license"
|
||||||
|
- "--output"
|
||||||
|
- "sbom.xml"
|
||||||
|
- "."
|
||||||
|
when:
|
||||||
|
- event: [push, tag]
|
||||||
|
|
||||||
|
upload_sbom:
|
||||||
|
image: quay.io/wollud1969/woodpecker-helper:0.5.1
|
||||||
|
environment:
|
||||||
DTRACK_API_KEY:
|
DTRACK_API_KEY:
|
||||||
from_secret: dtrack_api_key
|
from_secret: dtrack_api_key
|
||||||
DTRACK_API_URL:
|
DTRACK_API_URL:
|
||||||
from_secret: dtrack_api_url
|
from_secret: dtrack_api_url
|
||||||
commands:
|
commands:
|
||||||
- HOME=/home/`id -nu`
|
- cat sbom.xml
|
||||||
- |
|
|
||||||
trivy fs \
|
|
||||||
--server $TRIVY_URL \
|
|
||||||
--token $TRIVY_TOKEN \
|
|
||||||
--format cyclonedx \
|
|
||||||
--scanners license \
|
|
||||||
--output /tmp/sbom.xml \
|
|
||||||
.
|
|
||||||
- cat /tmp/sbom.xml
|
|
||||||
- |
|
- |
|
||||||
curl -X "POST" \
|
curl -X "POST" \
|
||||||
-H "Content-Type: multipart/form-data" \
|
-H "Content-Type: multipart/form-data" \
|
||||||
@ -43,7 +53,7 @@ steps:
|
|||||||
-F "autoCreate=true" \
|
-F "autoCreate=true" \
|
||||||
-F "projectName=$CI_REPO" \
|
-F "projectName=$CI_REPO" \
|
||||||
-F "projectVersion=$CI_COMMIT_SHA" \
|
-F "projectVersion=$CI_COMMIT_SHA" \
|
||||||
-F "bom=@/tmp/sbom.xml"\
|
-F "bom=@sbom.xml"\
|
||||||
"$DTRACK_API_URL/api/v1/bom"
|
"$DTRACK_API_URL/api/v1/bom"
|
||||||
when:
|
when:
|
||||||
- event: [push, tag]
|
- event: [push, tag]
|
||||||
|
Loading…
x
Reference in New Issue
Block a user