generate-srcinfo: merge grype commands

it can generate multiple formats in one go
This commit is contained in:
Christoph Reiter 2025-09-07 10:02:15 +02:00
parent 7395b7c769
commit a6d345ca35

View File

@ -91,8 +91,7 @@ jobs:
- name: Update vulnerability database
run: |
msys2-sbom create srcinfo.json.gz sbom.cdx.json
./bin/grype sbom:sbom.cdx.json -o cyclonedx-json --file sbom.vuln.cdx.json
./bin/grype sbom:sbom.cdx.json -o json --file sbom.grype.json
./bin/grype sbom:sbom.cdx.json -o cyclonedx-json=sbom.vuln.cdx.json -o json=sbom.grype.json
msys2-sbom merge sbom.cdx.json sbom.vuln.cdx.json --grype-json sbom.grype.json
- uses: actions/upload-artifact@v4