From afcf71cdb5638e4033d688a7f21c7f2b2f63b553 Mon Sep 17 00:00:00 2001 From: DeveloperDurp Date: Sun, 5 May 2024 11:24:25 -0500 Subject: [PATCH] update --- scripts/scanner/syft-docker.sh | 10 ++++++++++ templates/codescan.tpl.yml | 1 + 2 files changed, 11 insertions(+) create mode 100644 scripts/scanner/syft-docker.sh diff --git a/scripts/scanner/syft-docker.sh b/scripts/scanner/syft-docker.sh new file mode 100644 index 0000000..4130807 --- /dev/null +++ b/scripts/scanner/syft-docker.sh @@ -0,0 +1,10 @@ +#!/usr/bin/env bash +#%%MULTILINE_YAML_START +#Syft scan for go + +for i in packages/*.tar.gz; +do filename=${i%.*.tar.gz}; + filename=${filename##/}; + syft $i -o cyclonedx-json=$filename.docker.sbom.json; +done + diff --git a/templates/codescan.tpl.yml b/templates/codescan.tpl.yml index 4e8296b..68f5ae2 100644 --- a/templates/codescan.tpl.yml +++ b/templates/codescan.tpl.yml @@ -4,6 +4,7 @@ - ./scripts/scanner/syft-install.sh - ./scripts/scanner/syft-mkdir.sh - ./scripts/scanner/syft-go.sh + - ./scripts/scanner/syft-docker.sh artifacts: expire_in: 1 hour paths: