diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index b6709fa..a744f06 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -66,7 +66,7 @@ jobs: - name: Generate SBOM from Docker image if: inputs.dockerfile != '' - uses: anchore/sbom-action@v0.24 + uses: anchore/sbom-action@v0.24.2 with: image: localbuild/testimage:latest artifact-name: docker.cyclonedx.json @@ -123,7 +123,7 @@ jobs: - name: Generate SBOM from Python environment if: inputs.requirements != '' || inputs.pyproject != '' - uses: anchore/sbom-action@v0.24 + uses: anchore/sbom-action@v0.24.2 with: path: .sbom_venv artifact-name: python.cyclonedx.json diff --git a/.github/workflows/third-party-licenses.yml b/.github/workflows/third-party-licenses.yml index 341f0c1..28b1863 100644 --- a/.github/workflows/third-party-licenses.yml +++ b/.github/workflows/third-party-licenses.yml @@ -124,7 +124,7 @@ jobs: " - name: Generate SBOM from Docker image if: inputs.dockerfile != '' - uses: anchore/sbom-action@v0.24 + uses: anchore/sbom-action@v0.24.2 with: image: license-scan-image format: syft-json