diff --git a/.github/workflows/_reusable-sbom-scan.yml b/.github/workflows/_reusable-sbom-scan.yml index 2f2ff4ec..3a2a61b4 100644 --- a/.github/workflows/_reusable-sbom-scan.yml +++ b/.github/workflows/_reusable-sbom-scan.yml @@ -20,7 +20,7 @@ jobs: pip install poetry poetry install - name: Create SBOM - uses: anchore/sbom-action@62ad5284b8ced813296287a0b63906cb364b73ee # v0.22.0 + uses: anchore/sbom-action@deef08a0db64bfad603422135db61477b16cef56 # v0.22.1 with: format: spdx-json output-file: ${{ github.event.repository.name }}-sbom.spdx.json