Skip to content

Conversation

@prabhu
Copy link

@prabhu prabhu commented Sep 4, 2025

Currently, the workflow is testing the depscan v5 release, which has known limitations. In addition, cdxgen has known limitations generating SBOMs with the default temp directory in GitHub-hosted agents.

This PR updates the pip install to install the depscan v6 prerelease. In addition, the cdxgen temp directory is set via environment variables.

Updated to use depscan v6 beta. Setting CDXGEN_TEMP_DIR variable since SBOM generation would fail otherwise with disk space errors on GitHub hosted agents.

Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant