diff --git a/.github/workflows/dependency-scan.yml b/.github/workflows/dependency-scan.yml index 1b404e161..688e70b1e 100644 --- a/.github/workflows/dependency-scan.yml +++ b/.github/workflows/dependency-scan.yml @@ -1,11 +1,16 @@ name: Dependency Scan -on: pull_request +on: + pull_request: + push: + branches: + - main jobs: - dependency-scan: + generate-nodejs-sbom: runs-on: ubuntu-latest steps: + - uses: actions/checkout@v4 - name: Setup Go uses: actions/setup-go@v6 with: @@ -14,7 +19,14 @@ jobs: - name: Generate SBOM uses: launchdarkly/gh-actions/actions/dependency-scan/generate-sbom@main with: - types: 'go,nodejs' + types: 'nodejs' + evaluate-policy: + runs-on: ubuntu-latest + needs: + - generate-nodejs-sbom + steps: - name: Evaluate SBOM Policy uses: launchdarkly/gh-actions/actions/dependency-scan/evaluate-policy@main + with: + artifacts-pattern: bom-*