diff --git a/libraries/syft/steps/generate_sbom.groovy b/libraries/syft/steps/generate_sbom.groovy index 568f13d9..e3a08219 100644 --- a/libraries/syft/steps/generate_sbom.groovy +++ b/libraries/syft/steps/generate_sbom.groovy @@ -27,7 +27,7 @@ void call() { // perform the syft scan String archive_name = "${img.registry}-${img.repo}-${img.tag}.tar".replaceAll("/","-") String results_name = "${img.repo}-${img.tag}-${raw_results_file}".replaceAll("/","-") - sh "syft ${archive_name} -o json=${results_name}" + sh "syft ${archive_name} -o json > ${results_name}" // archive the results archiveArtifacts artifacts: "${results_name}" diff --git a/libraries/syft/test/GenerateSBOMSpec.groovy b/libraries/syft/test/GenerateSBOMSpec.groovy index c5cd645c..dfb82b7a 100644 --- a/libraries/syft/test/GenerateSBOMSpec.groovy +++ b/libraries/syft/test/GenerateSBOMSpec.groovy @@ -29,8 +29,8 @@ public class GenerateSBOMSpec extends JTEPipelineSpecification { when: GenerateSBOM() then: - 1 * getPipelineMock('sh').call('syft ghcr.io-boozallen-sdp-images-syft-latest.tar -o json=syft-latest-syft-sbom-results.json') - 1 * getPipelineMock('sh').call('syft ghcr.io-boozallen-sdp-images-grype-latest.tar -o json=grype-latest-syft-sbom-results.json') + 1 * getPipelineMock('sh').call('syft ghcr.io-boozallen-sdp-images-syft-latest.tar -o json > syft-latest-syft-sbom-results.json') + 1 * getPipelineMock('sh').call('syft ghcr.io-boozallen-sdp-images-grype-latest.tar -o json > grype-latest-syft-sbom-results.json') } def "Archives SBOM file as expected" () {