Skip to content

Commit 0585f53

Browse files
authored
chore: upgrade scancode-action to docker base v0.1 release (#2141)
Signed-off-by: tdruez <tdruez@aboutcode.org>
1 parent b46082b commit 0585f53

10 files changed

Lines changed: 15 additions & 15 deletions

.github/workflows/generate-sboms.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ jobs:
3636
find scancodeio/ -type f -name "*.ABOUT" -exec cp {} "${{ env.INPUTS_PATH }}/about-files/" \;
3737
3838
- name: Resolve the dependencies using ScanCode-action
39-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
39+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
4040
with:
4141
pipelines: "resolve_dependencies:DynamicResolver"
4242
inputs-path: ${{ env.INPUTS_PATH }}

.github/workflows/sca-integration-anchore.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ jobs:
4343
retention-days: 20
4444

4545
- name: Import SBOM into ScanCode.io
46-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
46+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
4747
with:
4848
pipelines: "load_sbom"
4949
inputs-path: "anchore-grype-sbom.cdx.json"

.github/workflows/sca-integration-cdxgen.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ jobs:
4646
retention-days: 20
4747

4848
- name: Import SBOM into ScanCode.io
49-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
49+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
5050
with:
5151
pipelines: "load_sbom"
5252
inputs-path: "cdxgen-sbom.cdx.json"

.github/workflows/sca-integration-cyclonedx-gomod.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ jobs:
4646
retention-days: 20
4747

4848
- name: Import SBOM into ScanCode.io
49-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
49+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
5050
with:
5151
pipelines: "load_sbom"
5252
inputs-path: "gomod-sbom.cdx.json"

.github/workflows/sca-integration-depscan.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ jobs:
5151
run: pip uninstall --yes owasp-depscan
5252

5353
- name: Import SBOM into ScanCode.io
54-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
54+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
5555
with:
5656
pipelines: "load_sbom"
5757
inputs-path: "reports/sbom-docker.vdr.json"

.github/workflows/sca-integration-ort-package-file.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
runs-on: ubuntu-24.04
2525
steps:
2626
- name: Analyze Docker image with ScanCode.io
27-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
27+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
2828
with:
2929
pipelines: "analyze_docker_image"
3030
input-urls:

.github/workflows/sca-integration-ort.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ jobs:
5757
reporter
5858
5959
- name: Import SBOM into ScanCode.io
60-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
60+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
6161
with:
6262
pipelines: "load_sbom"
6363
inputs-path: "${{ env.ORT_RESULTS_PATH }}/bom.cyclonedx.json"
@@ -96,7 +96,7 @@ jobs:
9696
reporter
9797
9898
- name: Import SBOM into ScanCode.io
99-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
99+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
100100
with:
101101
pipelines: "load_sbom"
102102
inputs-path: "${{ env.ORT_RESULTS_PATH }}/bom.cyclonedx.json"
@@ -158,7 +158,7 @@ jobs:
158158
name: npm-mime-types-2.1.26-ort-sboms
159159

160160
- name: Import SBOM into ScanCode.io
161-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
161+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
162162
with:
163163
pipelines: "load_sbom"
164164
inputs-path: "bom.cyclonedx.json"
@@ -184,7 +184,7 @@ jobs:
184184
name: npm-mime-types-2.1.26-ort-sboms
185185

186186
- name: Import SBOM into ScanCode.io
187-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
187+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
188188
with:
189189
pipelines: "load_sbom"
190190
inputs-path: "bom.cyclonedx.xml"
@@ -210,7 +210,7 @@ jobs:
210210
name: npm-mime-types-2.1.26-ort-sboms
211211

212212
- name: Import SBOM into ScanCode.io
213-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
213+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
214214
with:
215215
pipelines: "load_sbom"
216216
inputs-path: "bom.spdx.json"
@@ -236,7 +236,7 @@ jobs:
236236
name: npm-mime-types-2.1.26-ort-sboms
237237

238238
- name: Import SBOM into ScanCode.io
239-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
239+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
240240
with:
241241
pipelines: "load_sbom"
242242
inputs-path: "bom.spdx.yml"

.github/workflows/sca-integration-osv-scanner.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ jobs:
5151
retention-days: 20
5252

5353
- name: Import SBOM into ScanCode.io
54-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
54+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
5555
with:
5656
pipelines: "load_sbom"
5757
inputs-path: "osv-sbom.spdx.json"

.github/workflows/sca-integration-sbom-tool.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ jobs:
5252
path: sbom-output
5353

5454
- name: Import SBOM into ScanCode.io
55-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
55+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
5656
with:
5757
pipelines: "load_sbom"
5858
inputs-path: "sbom-output/_manifest/spdx_2.2/manifest.spdx.json"

.github/workflows/sca-integration-trivy.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ jobs:
4545
retention-days: 20
4646

4747
- name: Import SBOM into ScanCode.io
48-
uses: aboutcode-org/scancode-action@6e900c920928c44932e756e308561451b09ec58b
48+
uses: aboutcode-org/scancode-action@76777db8400d719de67ba3e465c5881037b45cb9 # v0.1
4949
with:
5050
pipelines: "load_sbom"
5151
inputs-path: "trivy-report.sbom.json"

0 commit comments

Comments
 (0)