Replace anchore/sbom-action with direct Syft CLI install
All checks were successful
CI/CD Pipeline - Apartment API / Scan Dependencies (pull_request) Successful in 13s
CI/CD Pipeline - Apartment API / Lint & Test (pull_request) Successful in 43s
CI/CD Pipeline - Apartment API / Send Webhook Notification (pull_request) Successful in 2s
CI/CD Pipeline - Apartment API / Build & Push Image (pull_request) Has been skipped
CI/CD Pipeline - Apartment API / Deploy to Production (pull_request) Has been skipped

The anchore/sbom-action GitHub Action uses upload-artifact@v4 internally,
which is not supported on GHES. Install Syft directly via CLI and run it
as a shell command to generate the SBOM without the artifact upload.
This commit is contained in:
2026-02-08 20:19:37 -07:00
parent 66f545bc75
commit 40b4dc50f1

View File

@ -264,12 +264,13 @@ jobs:
# ============================================================ # ============================================================
# SBOM Generation with Syft # SBOM Generation with Syft
# ============================================================ # ============================================================
- name: Install Syft
run: |
curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b /usr/local/bin
- name: Generate SBOM with Syft - name: Generate SBOM with Syft
uses: anchore/sbom-action@v0 run: |
with: syft ${{ steps.set-tag.outputs.full_image }} -o spdx-json=sbom.spdx.json
image: ${{ steps.set-tag.outputs.full_image }}
format: spdx-json
output-file: sbom.spdx.json
# ============================================================ # ============================================================
# Image Signing with Cosign # Image Signing with Cosign