Skip to content

Update owasp-dep-scan.yml #15

Update owasp-dep-scan.yml

Update owasp-dep-scan.yml #15

name: OWASP dep-scan demo
on:
push:
branches: ["main"]
jobs:
scan:
name: Create SBOM of .NET solution
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install and set up ORAS
uses: oras-project/setup-oras@v1
- name: Download vulnerability DB and dep-scan
run: |
oras pull ghcr.io/appthreat/vdb:v5 -o $RUNNER_TEMP
oras pull ghcr.io/appthreat/depscan:v4 -o $RUNNER_TEMP
chmod +x $RUNNER_TEMP/depscan
- name: Run depscan
env:
FETCH_LICENSE: true
run: |
$RUNNER_TEMP/depscan --src src --reports-dir $RUNNER_TEMP/reports --csaf --profile license-compliance
- uses: actions/upload-artifact@v4
with:
path: $RUNNER_TEMP/reports