You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
At the moment there are different SBOMs generated; one during the docker/build-push action stage that uses Syft and the integrated buildx SBOM function; an another one again using Syft but scanning the output image to eventually submit the results to the GitHub Dependency Submission API.
This issue is marked stale because it has been open for an extended period with no activity. Remove the 'stale' label or comment otherwise this issue will be closed in 7 days.
At the moment there are different SBOMs generated; one during the docker/build-push action stage that uses Syft and the integrated buildx SBOM function; an another one again using Syft but scanning the output image to eventually submit the results to the GitHub Dependency Submission API.
If issue docker/build-push-action#861 and/or docker/build-push-action#889 are solved this can be consolidated into the build-push stage.
As an alternative instead of scanning the image again, the attested SBOM could be retrieved and fed to the Dependency Submission API.
The text was updated successfully, but these errors were encountered: