generate-srcinfo: include fixed versions in the SBOM

See c7d0333481
This commit is contained in:
Christoph Reiter 2025-09-06 17:36:58 +02:00
parent a1e37ed1e2
commit 72b7663813

View File

@ -92,7 +92,8 @@ jobs:
run: |
msys2-sbom create srcinfo.json.gz sbom.cdx.json
./bin/grype sbom:sbom.cdx.json -o cyclonedx-json --file sbom.vuln.cdx.json
msys2-sbom merge sbom.cdx.json sbom.vuln.cdx.json
./bin/grype sbom:sbom.cdx.json -o json --file sbom.grype.json
msys2-sbom merge sbom.cdx.json sbom.vuln.cdx.json --grype-json sbom.grype.json
- uses: actions/upload-artifact@v4
with: