Skip to content
18 changes: 15 additions & 3 deletions .github/workflows/dependency-scan.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,16 @@
name: Dependency Scan

on: pull_request
on:
pull_request:
push:
branches:
- main

jobs:
dependency-scan:
generate-nodejs-sbom:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Go
uses: actions/setup-go@v6
with:
Expand All @@ -14,7 +19,14 @@ jobs:
- name: Generate SBOM
uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@main
with:
types: 'go,nodejs'
types: 'nodejs'

evaluate-policy:
runs-on: ubuntu-latest
needs:
- generate-nodejs-sbom
steps:
- name: Evaluate SBOM Policy
uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@main
with:
artifacts-pattern: bom-*
Loading