Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ First, configure your Datadog API and application keys by adding `DD_APP_KEY` an
Next, run SCA by following instructions for your chosen CI provider below.

## GitHub Actions
SCA can run as a job in your GitHub Actions workflows. The action provided below invokes [Datadog osv-scanner][10], our recommended SBOM generator, on your codebase and uploads the results into Datadog.
SCA can run as a job in your GitHub Actions workflows. The action provided below invokes Datadog's recommended SBOM tool, [Datadog SBOM Generator][10], on your codebase and uploads the results into Datadog.

Add the following code snippet in `.github/workflows/datadog-sca.yml`. Make sure to replace
the `dd_site` attribute with the [Datadog site][12] you are using.
Expand Down Expand Up @@ -120,18 +120,18 @@ export DD_SITE="{{< region-param key="dd_site" code="true" >}}"
# Install dependencies
npm install -g @datadog/datadog-ci

# Download the latest Datadog OSV Scanner:
# https://github.com/DataDog/osv-scanner/releases
DATADOG_OSV_SCANNER_URL=https://github.com/DataDog/osv-scanner/releases/latest/download/osv-scanner_linux_amd64.zip
# Download the latest Datadog SBOM Generator:
# https://github.com/DataDog/datadog-sbom-generator/releases
DATADOG_SBOM_GENERATOR_URL=https://github.com/DataDog/datadog-sbom-generator/releases/latest/download/datadog-sbom-generator_linux_amd64.zip

# Install OSV Scanner
mkdir /osv-scanner
curl -L -o /osv-scanner/osv-scanner.zip $DATADOG_OSV_SCANNER_URL
unzip /osv-scanner/osv-scanner.zip -d /osv-scanner
chmod 755 /osv-scanner/osv-scanner
# Install Datadog SBOM Generator
mkdir /datadog-sbom-generator
curl -L -o /datadog-sbom-generator/datadog-sbom-generator.zip $DATADOG_SBOM_GENERATOR_URL
unzip /datadog-sbom-generator/datadog-sbom-generator.zip -d /datadog-sbom-generator
chmod 755 /datadog-sbom-generator/datadog-sbom-generator

# Run OSV Scanner and scan your dependencies
/osv-scanner/osv-scanner --skip-git -r --experimental-only-packages --format=cyclonedx-1-5 --paths-relative-to-scan-dir --output=/tmp/sbom.json /path/to/repository
# Run Datadog SBOM Generator to scan your dependencies
/datadog-sbom-generator/datadog-sbom-generator scan --output=/tmp/sbom.json /path/to/repository

# Upload results to Datadog
datadog-ci sbom upload /tmp/sbom.json
Expand Down Expand Up @@ -232,7 +232,7 @@ You **must** run an analysis of your repository on the default branch before res

## Upload third-party SBOM to Datadog

While Datadog preferred SBOM generator is [our own osv-scanner fork][10], it is possible to ingest a
Datadog recommends using the [Datadog SBOM generator][10], but it is also possible to ingest a
third-party SBOM.

Our tooling supports the following SBOM standards:
Expand Down Expand Up @@ -334,7 +334,7 @@ If no services or teams are found, Datadog uses the `CODEOWNERS` file in your re
[7]: /integrations/github
[8]: /integrations/guide/source-code-integration
[9]: /security/code_security/dev_tool_int/github_pull_requests/
[10]: https://github.com/DataDog/osv-scanner
[10]: https://github.com/DataDog/datadog-sbom-generator
[11]: https://docs.github.com/en/actions/security-for-github-actions/security-guides
[12]: /getting_started/site/
[13]: https://github.com/DataDog/datadog-static-analyzer-github-action
Expand Down
7 changes: 3 additions & 4 deletions content/en/security/code_security/troubleshooting/_index.md
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,6 @@ For issues with Datadog Software Composition Analysis (SCA), include the followi
While the [Datadog SBOM generator][7] is recommended, Datadog supports the ingestion of any SBOM files. Please ensure your files adhere to either the Cyclone-DX 1.4 or Cyclone-DX 1.5 formats.

Ingestion of SBOM files is verified for the following third-party tools:
- [osv-scanner][7]
- [trivy][8]

To ingest your SBOM file into Datadog, follow the steps below:
Expand Down Expand Up @@ -157,10 +156,10 @@ You can always configure your default branch in-app under [Repository Settings][

### No package detected for C# projects

Our SBOM generator, ([`osv-scanner`][7]), extracts dependencies from a `packages.lock.json` file. If you do not have
The Datadog SBOM generator, ([`datadog-sbom-generator`][7]), extracts dependencies from a `packages.lock.json` file. If you do not have
this file, you can update your project definition to generate it. Follow these [instructions to update your project definition][9] to generate a `packages.lock.json` file.

The generated lock file is used by [`osv-scanner`][7] to extract dependencies and generate an SBOM.
The generated lock file is used by [`datadog-sbom-generator`][7] to extract dependencies and generate an SBOM.

### No results from Datadog-hosted scans for a repository using `git-lfs`

Expand Down Expand Up @@ -242,7 +241,7 @@ To disable IAST, remove the `DD_IAST_ENABLED=true` environment variable from you
[4]: https://app.datadoghq.com/source-code/repositories
[5]: https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=sarif
[6]: https://docs.datadoghq.com/security/code_security/static_analysis/setup/#diff-aware-scanning
[7]: https://github.com/DataDog/osv-scanner
[7]: https://github.com/DataDog/datadog-sbom-generator
[8]: https://github.com/aquasecurity/trivy
[9]: https://learn.microsoft.com/en-us/nuget/consume-packages/package-references-in-project-files#enabling-the-lock-file
[12]: https://app.datadoghq.com/security/appsec/vm/library
Expand Down