{"id":19368451,"url":"https://github.com/anchore/sbom-action","last_synced_at":"2026-03-09T21:01:37.203Z","repository":{"id":37077888,"uuid":"399925381","full_name":"anchore/sbom-action","owner":"anchore","description":"GitHub Action for creating software bill of materials using Syft.","archived":false,"fork":false,"pushed_at":"2026-02-19T13:32:33.000Z","size":10849,"stargazers_count":223,"open_issues_count":18,"forks_count":34,"subscribers_count":10,"default_branch":"main","last_synced_at":"2026-02-19T17:30:38.440Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/anchore.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2021-08-25T18:49:40.000Z","updated_at":"2026-02-19T13:51:07.000Z","dependencies_parsed_at":"2023-02-19T05:15:55.221Z","dependency_job_id":"41545399-86d3-481f-a1ba-cbd7677477f4","html_url":"https://github.com/anchore/sbom-action","commit_stats":{"total_commits":249,"total_committers":22,"mean_commits":"11.318181818181818","dds":0.570281124497992,"last_synced_commit":"df80a981bc6edbc4e220a492d3cbe9f5547a6e75"},"previous_names":[],"tags_count":67,"template":false,"template_full_name":null,"purl":"pkg:github/anchore/sbom-action","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anchore%2Fsbom-action","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anchore%2Fsbom-action/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anchore%2Fsbom-action/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anchore%2Fsbom-action/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/anchore","download_url":"https://codeload.github.com/anchore/sbom-action/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anchore%2Fsbom-action/sbom","scorecard":{"id":191524,"data":{"date":"2025-08-11","repo":{"name":"github.com/anchore/sbom-action","commit":"7b36ad622f042cab6f59a75c2ac24ccb256e9b45"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":4,"reason":"5 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 4","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: tests/fixtures/image-debian-match-coverage/java/example-java-app-maven-0.1.0.jar:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/oss-project-board-add.yaml:1","Warn: no topLevel permission defined: .github/workflows/release-draft.yml:1","Warn: no topLevel permission defined: .github/workflows/release-tag.yml:1","Warn: no topLevel permission defined: .github/workflows/remove-awaiting-response-label.yaml:1","Warn: no topLevel permission defined: .github/workflows/test.yml:1","Warn: no topLevel permission defined: .github/workflows/update-syft-release.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/anchore/.github/SECURITY.md:1","Info: Found linked content: github.com/anchore/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/anchore/.github/SECURITY.md:1","Info: Found text in security policy: github.com/anchore/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/oss-project-board-add.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/anchore/sbom-action/oss-project-board-add.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/remove-awaiting-response-label.yaml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/anchore/sbom-action/remove-awaiting-response-label.yaml/main?enable=pin","Warn: containerImage not pinned by hash: tests/fixtures/localbuild/Dockerfile:1: pin your Docker image by updating alpine:3.15.0 to alpine:3.15.0@sha256:21a3deaa0d32a8057914f36584b5288d2e5ecc984380bc0118285c70fa8c9300","Warn: npmCommand not pinned by hash: .github/workflows/update-syft-release.yml:24","Info:   5 out of   5 GitHub-owned GitHubAction dependencies pinned","Info:   4 out of   6 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned","Info:   2 out of   3 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.20.4 not signed: https://api.github.com/repos/anchore/sbom-action/releases/234042974","Warn: release artifact v0.20.3 not signed: https://api.github.com/repos/anchore/sbom-action/releases/232301873","Warn: release artifact v0.20.2 not signed: https://api.github.com/repos/anchore/sbom-action/releases/229482191","Warn: release artifact v0.20.1 not signed: https://api.github.com/repos/anchore/sbom-action/releases/224111304","Warn: release artifact v0.20.4 does not have provenance: https://api.github.com/repos/anchore/sbom-action/releases/234042974","Warn: release artifact v0.20.3 does not have provenance: https://api.github.com/repos/anchore/sbom-action/releases/232301873","Warn: release artifact v0.20.2 does not have provenance: https://api.github.com/repos/anchore/sbom-action/releases/229482191","Warn: release artifact v0.20.1 does not have provenance: https://api.github.com/repos/anchore/sbom-action/releases/224111304"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/test.yml:59"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"13 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-h5c3-5r3r-rr8q","Warn: Project is vulnerable to: GHSA-rmvr-2pp2-xj38","Warn: Project is vulnerable to: GHSA-xx4v-prfh-6cgc","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-3jfq-g458-7qm9","Warn: Project is vulnerable to: GHSA-r628-mhmh-qjhw","Warn: Project is vulnerable to: GHSA-9r2w-394v-53qc","Warn: Project is vulnerable to: GHSA-5955-9wpr-37jh","Warn: Project is vulnerable to: GHSA-qq89-hq3f-393p","Warn: Project is vulnerable to: GHSA-f5x3-32g6-xq36","Warn: Project is vulnerable to: GHSA-w5p7-h5w8-2hfq"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-16T20:47:59.033Z","repository_id":37077888,"created_at":"2025-08-16T20:47:59.033Z","updated_at":"2025-08-16T20:47:59.033Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30312116,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-09T20:05:46.299Z","status":"ssl_error","status_checked_at":"2026-03-09T19:57:04.425Z","response_time":61,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-10T08:06:28.136Z","updated_at":"2026-03-09T21:01:37.154Z","avatar_url":"https://github.com/anchore.png","language":"TypeScript","funding_links":[],"categories":["TypeScript"],"sub_categories":[],"readme":"# GitHub Action for SBOM Generation\n\n**A GitHub Action for creating a software bill of materials (SBOM) using [Syft](https://github.com/anchore/syft).**\n\n[![GitHub release](https://img.shields.io/github/release/anchore/sbom-action.svg)](https://github.com/anchore/sbom-action/releases/latest)\n[![License: Apache-2.0](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://github.com/anchore/sbom-action/blob/main/LICENSE)\n[![Join our Discourse](https://img.shields.io/badge/Discourse-Join-blue?logo=discourse)](https://anchore.com/discourse)\n\n## Basic Usage\n\n```yaml\n- uses: anchore/sbom-action@v0\n```\n\nBy default, this action will execute a Syft scan in the workspace directory\nand upload a workflow artifact SBOM in SPDX format. It will also detect\nif being run during a [GitHub release](https://docs.github.com/en/repositories/releasing-projects-on-github/about-releases)\nand upload the SBOM as a release asset.\n\n\u003e [!IMPORTANT]\n\u003e To upload the SBOM to releases, you will need to give the action permission to read the artifact from the action, and write it to the release:\n\u003e ```yaml\n\u003e jobs:\n\u003e  build:\n\u003e    permissions:\n\u003e      actions: read\n\u003e      contents: write\n\u003e    steps:\n\u003e ```\n\n## Example Usage\n\n### Scan a container image\n\nTo scan a container image, use the `image` parameter:\n\n```yaml\n- uses: anchore/sbom-action@v0\n  with:\n    image: ghcr.io/example/image_name:tag\n```\n\nThe image will be fetched using the Docker daemon if available,\nwhich will use any authentication available to the daemon.\n\nIf the Docker daemon is not available, the action will retrieve the image\ndirectly from the container registry.\n\nIt is also possible to directly connect to the container registry with the\n`registry-username` and `registry-password` parameters. This will always bypass the\nDocker daemon:\n\n```yaml\n- uses: anchore/sbom-action@v0\n  with:\n    image: my-registry.com/my/image\n    registry-username: mr_awesome\n    registry-password: ${{ secrets.REGISTRY_PASSWORD }}\n```\n\n### Scan a specific directory\n\nUse the `path` parameter, relative to the repository root:\n\n```yaml\n- uses: anchore/sbom-action@v0\n  with:\n    path: ./build/\n```\n\n### Scan a specific file\n\nUse the `file` parameter, relative to the repository root:\n\n```yaml\n- uses: anchore/sbom-action@v0\n  with:\n    file: ./build/file\n```\n\n### Publishing SBOMs with releases\n\nThe `sbom-action` will detect being run during a\n[GitHub release](https://docs.github.com/en/repositories/releasing-projects-on-github/about-releases)\nand automatically upload all SBOMs as release assets. However,\nit may be desirable to upload SBOMs generated with other tools or using Syft\noutside this action. To do this, use the `anchore/sbom-action/publish-sbom` sub-action\nand specify a regular expression with the `sbom-artifact-match`\nparameter:\n\n```yaml\n- uses: anchore/sbom-action/publish-sbom@v0\n  with:\n    sbom-artifact-match: \".*\\\\.spdx$\"\n```\n\n### Naming the SBOM output\n\nBy default, this action will upload an artifact named\n`\u003crepo\u003e-\u003cjob-name\u003e[-\u003cstep-id|step-number\u003e].\u003cextension\u003e`, for\nexample:\n\n```yaml\nbuild-sbom:\n  steps:\n    - uses: anchore/sbom-action@v0\n    - uses: anchore/sbom-action@v0\n    - uses: anchore/sbom-action@v0\n      id: myid\n```\n\nWill create 3 artifacts:\n\n```text\nmy-repo-build-sbom.spdx.json\nmy-repo-build-sbom-2.spdx.json\nmy-repo-build-sbom-myid.spdx.json\n```\n\nYou may need to name these artifacts differently, simply\nuse the `artifact-name` parameter:\n\n```yaml\n- uses: anchore/sbom-action@v0\n  with:\n    artifact-name: sbom.spdx\n```\n\n\u003e [!IMPORTANT]  \n\u003e If using this action within a **matrix build**, you must specify a unique `artifact-name`\n\u003e based on matrix parameters or the artifact upload will fail due to duplicate names. See\n\u003e an [example here](.github/workflows/test.yml#L36).\n\n## Permissions\n\nThis action needs the following permissions, depending on how it is being used:\n\n```\ncontents: write # for sbom-action artifact uploads\n```\n\nIf attaching release assets, the `actions: read` permission is also required.\nThis may be implicit for public repositories, but is likely to be necessary for\nprivate repositories.\n\n```\nactions: read # to find workflow artifacts when attaching release assets\n```\n\n## Configuration\n\n### anchore/sbom-action\n\nThe main [SBOM action](action.yml), responsible for generating SBOMs\nand uploading them as workflow artifacts and release assets.\n\n| Parameter                   | Description                                                                                                                                             | Default                          |\n| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------- |\n| `path`                      | A path on the filesystem to scan. This is mutually exclusive to `file` and `image`.                                                                     | \\\u003ccurrent directory\u003e             |\n| `file`                      | A file on the filesystem to scan. This is mutually exclusive to `path` and `image`.                                                                     |                                  |\n| `image`                     | A container image to scan. This is mutually exclusive to `path` and `file`. See [Scan a container image](#scan-a-container-image) for more information. |                                  |\n| `registry-username`         | The registry username to use when authenticating to an external registry                                                                                |                                  |\n| `registry-password`         | The registry password to use when authenticating to an external registry                                                                                |                                  |\n| `artifact-name`             | The name to use for the generated SBOM artifact. See: [Naming the SBOM output](#naming-the-sbom-output)                                                 | `sbom-\u003cjob\u003e-\u003cstep-id\u003e.spdx.json` |\n| `output-file`               | The location to output a resulting SBOM                                                                                                                 |                                  |\n| `format`                    | The SBOM format to export. One of: `spdx`, `spdx-json`, `cyclonedx`, `cyclonedx-json`                                                                   | `spdx-json`                      |\n| `dependency-snapshot`       | Whether to upload the SBOM to the GitHub Dependency submission API                                                                                      | `false`                          |\n| `upload-artifact`           | Upload artifact to workflow                                                                                                                             | `true`                           |\n| `upload-artifact-retention` | Retention policy in days for uploaded artifact to workflow.                                                                                             |                                  |\n| `upload-release-assets`     | Upload release assets                                                                                                                                   | `true`                           |\n| `syft-version`              | The version of Syft to use                                                                                                                              |                                  |\n| `github-token`              | Authorized secret GitHub Personal Access Token.                                                                                                         | `github.token`                   |\n| `config `                   | Syft configuration file to use.                                                                                                                         |                                  |\n\n### anchore/sbom-action/publish-sbom\n\nA sub-action to [upload multiple SBOMs](publish-sbom/action.yml) to GitHub releases.\n\n| Parameter             | Description                       | Default             |\n| --------------------- | --------------------------------- | ------------------- |\n| `sbom-artifact-match` | A pattern to find SBOM artifacts. | `.*\\\\.spdx\\\\.json$` |\n\n### anchore/sbom-action/download-syft\n\nA sub-action to [download Syft](download-syft/action.yml).\n\n| Parameter      | Description                     | Default |\n| -------------- | ------------------------------- | ------- |\n| `syft-version` | The version of Syft to download |         |\n\nOutput parameters:\n\n| Parameter | Description                                                        |\n| --------- | ------------------------------------------------------------------ |\n| `cmd`     | a reference to the [Syft](https://github.com/anchore/syft) binary. |\n\n`cmd` can be referenced in a workflow like other output parameters:\n`${{ steps.\u003cstep-id\u003e.outputs.cmd }}`\n\n## Windows\n\nThis action is tested on Windows, and should work natively on Windows hosts\nwithout WSL. (Note that it previously required WSL, but should now be run\nnatively on Windows.)\n\n## Diagnostics\n\nThis action makes extensive use of GitHub Action debug logging,\nwhich can be enabled as [described here](https://github.com/actions/toolkit/blob/master/docs/action-debugging.md)\nby setting a secret in your repository of `ACTIONS_STEP_DEBUG` to `true`.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanchore%2Fsbom-action","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fanchore%2Fsbom-action","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanchore%2Fsbom-action/lists"}