From 24d432269f155b301ba9fa8b87def8a37fe42033 Mon Sep 17 00:00:00 2001 From: deusebio Date: Thu, 3 Oct 2024 19:05:42 +0200 Subject: [PATCH] [DPE-5585] SBOM Generation (#25) --- .github/workflows/trivy.yml | 30 +++++++++++++++++++++++++----- 1 file changed, 25 insertions(+), 5 deletions(-) diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index e0174cc..27f6830 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -8,16 +8,17 @@ jobs: build: uses: ./.github/workflows/build.yaml scan: - name: Trivy scan + name: Trivy scan and SBOM Generation needs: build - runs-on: ubuntu-20.04 + runs-on: ubuntu-22.04 steps: - name: Checkout code - uses: actions/checkout@v3 - - name: Install dependencies + uses: actions/checkout@v4 + - name: Install rockcraft (for skopeo) run: | sudo snap install rockcraft --classic --edge - - uses: actions/download-artifact@v3 + - name: Download artifact + uses: actions/download-artifact@v3 with: name: charmed-kafka - name: Import locally @@ -39,3 +40,22 @@ jobs: if: always() with: sarif_file: 'trivy-results.sarif' + + - name: Run Trivy in GitHub SBOM mode and submit results to Dependency Graph + uses: aquasecurity/trivy-action@master + with: + scan-type: 'image' + format: 'spdx-json' + output: 'dependency-results.sbom.json' + image-ref: 'trivy/charmed-kafka:test' + github-pat: ${{ secrets.GITHUB_TOKEN }} + severity: "MEDIUM,HIGH,CRITICAL" + scanners: "vuln" + + - name: Upload trivy report as a Github artifact + uses: actions/upload-artifact@v4 + with: + name: trivy-sbom-report + path: '${{ github.workspace }}/dependency-results.sbom.json' + retention-days: 90 +