From 17a52db09380d2b4e8c534cc3059db6186fc12f3 Mon Sep 17 00:00:00 2001 From: Zhe Sun <31067185+ZheSun88@users.noreply.github.com> Date: Fri, 16 Aug 2024 11:07:47 +0300 Subject: [PATCH] test latest version of cyclonedx-maven-plugin (#6670) * test latest version of cyclonedx-maven-plugin * Use bomber 0.5.0 --- .github/workflows/sbom.yml | 6 +++--- scripts/generateAndCheckSBOM.js | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/sbom.yml b/.github/workflows/sbom.yml index 9ee59b9f3..cd54135c5 100644 --- a/.github/workflows/sbom.yml +++ b/.github/workflows/sbom.yml @@ -71,9 +71,9 @@ jobs: go-version: 'stable' - run: go install github.com/google/osv-scanner/cmd/osv-scanner@v1 - run: | - wget -q https://github.com/devops-kung-fu/bomber/releases/download/v0.4.7/bomber_0.4.7_linux_amd64.deb - sudo dpkg -i bomber_0.4.7_linux_amd64.deb - name: Install bomber-0.4.7 + wget -q https://github.com/devops-kung-fu/bomber/releases/download/v0.5.0/bomber_0.5.0_linux_amd64.deb + sudo dpkg -i bomber_0.5.0_linux_amd64.deb + name: Install bomber-0.5.0 - run: | # Install dependency-check-9.0.2 cd /tmp diff --git a/scripts/generateAndCheckSBOM.js b/scripts/generateAndCheckSBOM.js index b89d5dc57..a19bc0cbf 100755 --- a/scripts/generateAndCheckSBOM.js +++ b/scripts/generateAndCheckSBOM.js @@ -520,7 +520,7 @@ async function main() { fs.writeFileSync("package.json","{}"); await run('mvn clean package -ntp -B -Pproduction -DskipTests -q'); await run('mvn dependency:tree -ntp -B', { output: 'target/tree-maven.txt' }); - await run('mvn -ntp -B org.cyclonedx:cyclonedx-maven-plugin:2.8.0:makeAggregateBom -q'); + await run('mvn -ntp -B org.cyclonedx:cyclonedx-maven-plugin:makeAggregateBom -q'); await run('npm ls --depth 6', { output: 'target/tree-npm.txt' }); await run('npm install --silent'); await run('npm install --silent --save-dev @cyclonedx/cyclonedx-npm');