Skip to content

Latest commit

 

History

History
77 lines (66 loc) · 3.93 KB

File metadata and controls

77 lines (66 loc) · 3.93 KB

sbom-scan.yml

This workflow will create a Software Bill of Materials (SBOM) for the repository using the anchore/sbom-action Action and then scan the SBOM using the anchore/scan-action Action. It runs on the ubuntu-latest runner label, uses the default version of Python available on the runner, and will use the latest compatible version of poetry to generate the lock file for the calling repository's Python package.

By default, every vulnerability found in the SBOM fails the build and is uploaded as SARIF (to the workflow artifact and the GitHub Security tab). Callers can opt in to treat only selected Poetry dependency groups as production: vulnerabilities in those groups still fail the build and appear in SARIF, while vulnerabilities found only in other (development) groups are reported as workflow warnings and are omitted from the uploaded SARIF.

Important

In order to use this workflow, the Python package must be using the Poetry package manager.

Important

When calling this reusable workflow, the permissions must be set as follows:

permissions:
  security-events: write
  contents: write
  id-token: write
  attestations: write

Note

This workflow uses the following GitHub Actions:

See the Workflow file for the currently used versions of each GitHub Action.

Tip

See the Workflow file for implementation details.

Inputs

Input variable Necessity Description Default
pre-install-python-packages optional Pre-install the specified Python packages before creating the SBOM (this string will be directly passed to pip install). ''
production-dependency-groups optional Comma-separated list of Poetry dependency groups treated as production. When set, only vulnerabilities in these groups fail the build and appear in the uploaded SARIF; vulnerabilities found only in other groups are reported as workflow warnings. When empty, every vulnerability fails the build. ''

Example

name: Create & Scan SBOM
on:
  push:
    branches: [main]
  pull_request:
    branches: [main]
  release:
    types: [published]
jobs:
  sbom-scan:
    uses: tektronix/python-package-ci-cd/.github/workflows/_reusable-sbom-scan.yml@v1.10.1
    with:
      production-dependency-groups: main
    permissions:
      security-events: write
      contents: write
      id-token: write
      attestations: write