diff --git a/.github/workflows/sbom_generator.yml b/.github/workflows/sbom_generator.yml new file mode 100644 index 000000000..856f31e3d --- /dev/null +++ b/.github/workflows/sbom_generator.yml @@ -0,0 +1,25 @@ +name: SBOM Generator + +on: + push: + branches: [ "main" ] + + workflow_dispatch: + +permissions: read-all + +jobs: + build: + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v3 + + - uses: advanced-security/sbom-generator-action@v0.0.1 + id: sbom + env: + GITHUB_TOKEN: ${{ github.token }} + - uses: actions/upload-artifact@v3.1.0 + with: + path: ${{steps.sbom.outputs.fileName }} + name: "SBOM"