From eb23b2608632216d09f949234f18a507028bcf42 Mon Sep 17 00:00:00 2001 From: Guilhem Bonnefille <guilhem.bonnefille@csgroup.eu> Date: Wed, 10 Jul 2024 07:53:15 +0000 Subject: [PATCH] feat(sbom): update default SBOM options to include Java catalogers when using the Jib variant As Jib generates Docker images embedding Jar application, the Java catalogers should be activated by default. Nix cataloger added. --- kicker.json | 2 +- templates/gitlab-ci-maven-jib.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/kicker.json b/kicker.json index 6f9d03d..6da98c7 100644 --- a/kicker.json +++ b/kicker.json @@ -266,7 +266,7 @@ { "name": "MAVEN_SBOM_OPTS", "description": "Options for syft used for SBOM analysis", - "default": "--catalogers rpm-db-cataloger,alpmdb-cataloger,apkdb-cataloger,dpkgdb-cataloger,portage-cataloger", + "default": "--override-default-catalogers rpm-db-cataloger,alpm-db-cataloger,apk-db-cataloger,dpkg-db-cataloger,portage-cataloger,nix-store-cataloger,java", "advanced": true } ] diff --git a/templates/gitlab-ci-maven-jib.yml b/templates/gitlab-ci-maven-jib.yml index 93fbbe4..05544cb 100644 --- a/templates/gitlab-ci-maven-jib.yml +++ b/templates/gitlab-ci-maven-jib.yml @@ -52,7 +52,7 @@ spec: default: registry.hub.docker.com/anchore/syft:debug sbom-opts: description: Options for syft used for SBOM analysis - default: --catalogers rpm-db-cataloger,alpmdb-cataloger,apkdb-cataloger,dpkgdb-cataloger,portage-cataloger + default: --override-default-catalogers rpm-db-cataloger,alpm-db-cataloger,apk-db-cataloger,dpkg-db-cataloger,portage-cataloger,nix-store-cataloger,java --- variables: MAVEN_SBOM_IMAGE: $[[ inputs.sbom-image ]] -- GitLab