sonarsource/CycloneDX SBOM action

Generate CycloneDX SBOM with Syft

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
imageThe Docker image to scan.yes
filenameThe generated SBOM file nameyes
upload-artifactAttach the SBOM to the workflownotrue
upload-release-assetsCreate release and attach the SBOM. Ignored if the release is already published (non-draft).notrue
release-tagTag name of the release to attach the SBOM to. Defaults to the tag from GITHUB_REF. Use when the workflow is not running on a tag ref (e.g. workflow_dispatch from a branch).no
syft-versionSyft versionnov1.41.2
registry-usernameRegistry usernameno
registry-passwordRegistry passwordno

no outputs