Skip to content

feat: [SEC-7263] Add dependency-scan GitHub Actions workflow #2

feat: [SEC-7263] Add dependency-scan GitHub Actions workflow

feat: [SEC-7263] Add dependency-scan GitHub Actions workflow #2

name: Dependency Scan
on:
pull_request:
push:
branches:
- main
jobs:
generate-nodejs-sbom:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4
- name: Generate SBOM
uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@main
with:
types: 'nodejs'
evaluate-policy:
runs-on: ubuntu-latest
needs:
- generate-nodejs-sbom
steps:
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4
- name: Evaluate SBOM Policy
uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@main
with:
artifacts-pattern: bom-*