Skip to content

Conversation

prabhu
Copy link

@prabhu prabhu commented Sep 4, 2025

Currently, the workflow is testing the depscan v5 release, which has known limitations. In addition, cdxgen has known limitations generating SBOMs with the default temp directory in GitHub-hosted agents.

This PR updates the pip install to install the depscan v6 prerelease. In addition, the cdxgen temp directory is set via environment variables.

Updated to use depscan v6 beta. Setting CDXGEN_TEMP_DIR variable since SBOM generation would fail otherwise with disk space errors on GitHub hosted agents.

Signed-off-by: Prabhu Subramanian <[email protected]>
Signed-off-by: Prabhu Subramanian <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant