Skip to content

Bump io.jenkins.tools.bom:bom-2.479.x from 3893.v213a_42768d35 to 4136.vca_c3202a_7fd1 #618

Bump io.jenkins.tools.bom:bom-2.479.x from 3893.v213a_42768d35 to 4136.vca_c3202a_7fd1

Bump io.jenkins.tools.bom:bom-2.479.x from 3893.v213a_42768d35 to 4136.vca_c3202a_7fd1 #618

Workflow file for this run

name: Third Party License Check
on:
push:
branches:
- master
pull_request:
branches:
- master
jobs:
validate-sbom:
runs-on: ubuntu-latest
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Set up JDK 17
uses: actions/setup-java@v4
with:
java-version: 17
distribution: adopt
- name: Generate json bom
run: mvn clean cyclonedx:makeAggregateBom -f pom.xml
- name: Check license compliance against allowlist
run: |
python config/check_dependencies.py \
--allowlist="config/allowed_licenses.json" \
--sbom="target/sbom.json" \
--schema="config/allowlist_schema.json"