diff --git a/README.md b/README.md index 4c76e30a57cd4e433e8f9c81dc2a13cf54c66e43..72154efaf9b9decb455066cb693e775158929699 100644 --- a/README.md +++ b/README.md @@ -277,7 +277,7 @@ It is bound to the `test` stage, and uses the following variables: | `TBC_SBOM_MODE` | Controls when SBOM reports are generated (`onrelease`: only on `$INTEG_REF`, `$PROD_REF` and `$RELEASE_REF` pipelines; `always`: any pipeline).<br/>:warning: `sbom-disabled` / `PYTHON_SBOM_DISABLED` takes precedence | `onrelease` | | `sbom-syft-url` / `PYTHON_SBOM_SYFT_URL` | Url to the `tar.gz` package for `linux_amd64` of Syft to use (ex: `https://github.com/anchore/syft/releases/download/v0.62.3/syft_0.62.3_linux_amd64.tar.gz`)<br/>_When unset, the latest version will be used_ | _none_ | | `sbom-name` / `PYTHON_SBOM_NAME` | Component name of the emitted SBOM | `$CI_PROJECT_PATH/$PYTHON_PROJECT_DIR` | -| `sbom-opts` / `PYTHON_SBOM_OPTS` | Options for syft used for SBOM analysis | `--override-default-catalogers python-package-cataloger` | +| `sbom-opts` / `PYTHON_SBOM_OPTS` | Options for syft used for SBOM analysis | `--override-default-catalogers python-package-cataloger --select-catalogers -file` | In addition to logs in the console, this job produces the following reports, kept for one week: diff --git a/kicker.json b/kicker.json index 45652d472cf608a94a0b4a5f92ea400d870b0a15..cbbce64b1fd9d2e01099912ae3252a7360b2657d 100644 --- a/kicker.json +++ b/kicker.json @@ -184,7 +184,7 @@ { "name": "PYTHON_SBOM_OPTS", "description": "Options for syft used for SBOM analysis", - "default": "--override-default-catalogers python-package-cataloger", + "default": "--override-default-catalogers python-package-cataloger --select-catalogers -file", "advanced": true } ] diff --git a/templates/gitlab-ci-python.yml b/templates/gitlab-ci-python.yml index 73bec36ac60c2303a8024d36c28a0d6ad4db8b2d..3e859620146b0c9c4f825cdd2228cbc70b2a0cd6 100644 --- a/templates/gitlab-ci-python.yml +++ b/templates/gitlab-ci-python.yml @@ -125,7 +125,7 @@ spec: default: $CI_PROJECT_PATH/$PYTHON_PROJECT_DIR sbom-opts: description: Options for syft used for SBOM analysis - default: --override-default-catalogers python-package-cataloger + default: --override-default-catalogers python-package-cataloger --select-catalogers -file release-enabled: description: Enable Release type: boolean