Skip to content

Update msft-sbom-tool.yml #10

Update msft-sbom-tool.yml

Update msft-sbom-tool.yml #10

name: OWASP dep-scan demo
on:
push:
branches: ["main"]
jobs:
scan:
name: Create SBOM of .NET solution
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install and set up ORAS
uses: oras-project/setup-oras@v1
- name: Download vulnerability DB and dep-scan
run: |
oras pull ghcr.io/appthreat/vdb:v5 -o $RUNNER_TEMP
oras pull ghcr.io/appthreat/depscan:v4 -o $RUNNER_TEMP
- name: Run depscan
env:
FETCH_LICENSE: true
run: |
cd src
$RUNNER_TEMP/depscan --src ReactAndAspNetCoreApp.sln --reports-dir ./reports --csaf --profile license-compliance
- uses: actions/upload-artifact@v4
with:
path: ./reports