diff --git a/README.md b/README.md index cc02d3381d3c30d0a1741eed714c4f083b91592d..7fea6162b8e587283e84d749981a0481775bebc4 100644 --- a/README.md +++ b/README.md @@ -458,7 +458,7 @@ It is bound to the `package-test` stage, and uses the following variables: | `sbom-disabled` / `DOCKER_SBOM_DISABLED` | Set to `true` to disable this job | _none_ | | `TBC_SBOM_MODE` | Controls when SBOM reports are generated (`onrelease`: only on `$INTEG_REF`, `$PROD_REF` and `$RELEASE_REF` pipelines; `always`: any pipeline).<br/>:warning: `sbom-disabled` / `DOCKER_SBOM_DISABLED` takes precedence | `onrelease` | | `sbom-image` / `DOCKER_SBOM_IMAGE` | The docker image used to emit SBOM | `registry.hub.docker.com/anchore/syft:debug`<br/>[](https://to-be-continuous.gitlab.io/doc/secu/trivy-DOCKER_SBOM_IMAGE)| -| `sbom-opts` / `DOCKER_SBOM_OPTS` | Options for syft used for SBOM analysis | `--override-default-catalogers rpm-db-cataloger,alpm-db-cataloger,apk-db-cataloger,dpkg-db-cataloger,portage-cataloger` | +| `sbom-opts` / `DOCKER_SBOM_OPTS` | Options for syft used for SBOM analysis | `--override-default-catalogers rpm-db-cataloger,alpm-db-cataloger,apk-db-cataloger,dpkg-db-cataloger,portage-cataloger --select-catalogers -file` | ### `docker-publish` job diff --git a/kicker.json b/kicker.json index 22439e11b8fec91cb3e33c7bae62058c1eb08a82..7bc910f35b2dd6cdc125cddb1265712c9c11ce17 100644 --- a/kicker.json +++ b/kicker.json @@ -212,7 +212,7 @@ { "name": "DOCKER_SBOM_OPTS", "description": "Options for syft used for SBOM analysis", - "default": "--override-default-catalogers rpm-db-cataloger,alpm-db-cataloger,apk-db-cataloger,dpkg-db-cataloger,portage-cataloger", + "default": "--override-default-catalogers rpm-db-cataloger,alpm-db-cataloger,apk-db-cataloger,dpkg-db-cataloger,portage-cataloger --select-catalogers -file", "advanced": true } ] diff --git a/templates/gitlab-ci-docker.yml b/templates/gitlab-ci-docker.yml index f5b9ed82356e6b5e28f722127e07beb93453a353..7a4ed27a442ad5f9fb6562bd22c42a0e901239c2 100644 --- a/templates/gitlab-ci-docker.yml +++ b/templates/gitlab-ci-docker.yml @@ -169,7 +169,7 @@ spec: default: registry.hub.docker.com/anchore/syft:debug sbom-opts: description: Options for syft used for SBOM analysis - default: --override-default-catalogers rpm-db-cataloger,alpm-db-cataloger,apk-db-cataloger,dpkg-db-cataloger,portage-cataloger + default: --override-default-catalogers rpm-db-cataloger,alpm-db-cataloger,apk-db-cataloger,dpkg-db-cataloger,portage-cataloger --select-catalogers -file --- # default workflow rules: Merge Request pipelines workflow: