Skip to content

CI: generate Syft SBOM and import into Sonar SCA#2

Open
sylvain-combe-sonarsource wants to merge 9 commits into4.xfrom
adhoc/syft-sbom-sca
Open

CI: generate Syft SBOM and import into Sonar SCA#2
sylvain-combe-sonarsource wants to merge 9 commits into4.xfrom
adhoc/syft-sbom-sca

Conversation

@sylvain-combe-sonarsource
Copy link
Copy Markdown

What

  • Generate a CycloneDX SBOM via Syft in the workflow
  • Dump SBOM (truncated) to Actions logs for troubleshooting
  • Run Sonar scan in verbose mode and import SBOM for SCA (sonar.sca.sbomImportPaths)

Notes

  • Uses SonarSource/sonarqube-scan-action@v7.0.0 + install-build-wrapper@v7.0.0 (replaces deprecated sonarqube-github-c-cpp)
  • Does not install Java/Node explicitly; relies on scanner JRE auto-provisioning

@sylvain-combe-sonarsource
Copy link
Copy Markdown
Author

No dependency worth analyzing.

@sonar-nautilus
Copy link
Copy Markdown

sonar-nautilus bot commented Jan 6, 2026

Quality Gate failed Quality Gate failed

Failed conditions
2 Security Hotspots

See analysis details on SonarQube

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant