diff --git a/jobs/codescan.yml b/jobs/codescan.yml index d130312..ca56b64 100644 --- a/jobs/codescan.yml +++ b/jobs/codescan.yml @@ -20,6 +20,16 @@ syft go.mod -o cyclonedx-json=syft/${CI_PROJECT_NAME}.sbom.json fi # End of syft-go.sh + + # Begin of syft-docker.sh + - | + #Syft scan for go + for i in packages/*.tar.gz; + do filename=${i%.*.tar.gz}; + filename=${filename##/}; + syft $i -o cyclonedx-json=$filename.docker.sbom.json; + done + # End of syft-docker.sh artifacts: expire_in: 1 hour paths: