Skip to main content

Goal

For every release, publish a Software Bill of Materials (SBOM) in both common formats:
  • CycloneDX 1.7, with components, licences, evidence, and known vulnerabilities
  • SPDX 2.3, with components and licences
Keep the scanoss-cli raw inventory as well, so you can refresh the SBOM later without scanning again.

When to use it

  • A customer, a regulation, or your own policy asks for an SBOM with each release.
  • You want a single record of what a release contained, stored next to the release.

Prerequisites

  • scanoss-cli, jq, and SCANOSS_API_KEY (see Recipes)
  • The source tree checked out at the release tag
  • Optional: a scanoss.json with your approvals, so the SBOM marks approved components

The script

Save this as ci/scanoss-release-sbom.sh and run it from the repository root in your release job.

What each step does

  1. Scan once. scan . fingerprints the release, matches it against the SCANOSS Knowledge Base, and writes the raw inventory. --include adds three layers:
    • deps: dependencies declared in manifest files such as package.json or go.mod, resolved through the API. They appear with "scope": "declared".
    • licenses: the licences of every component, detected or declared.
    • vulns: known vulnerabilities for every component.
  2. Convert. scanoss-cli sbom reads the inventory and writes the requested format. It does not contact the API, so it is fast and gives the same result each time. --format is required.
  3. Check. jq -e exits non-zero if a file is not the expected format, so the job stops before it publishes a broken SBOM.
  4. Checksums. A SHA256SUMS file lets consumers confirm they have the files you published.
Attach the files in sbom/ to the release, or upload them to wherever you store release artefacts.

What the output means

What each format can hold differs: A component that is both detected in your code and declared in a manifest appears once. Components approved in scanoss.json carry the scanoss:identified property in CycloneDX.

How it fails the pipeline

The script uses set -euo pipefail, so it stops at the first failing command: An SBOM documents what a release contains. It does not decide whether the release is allowed. To block a release on licences or vulnerabilities, run the licence and vulnerability gate on inventory-<version>.json before you publish:

Variations

  • One format only. Skip the raw inventory and scan straight into a format: scanoss-cli scan . --include deps,licenses,vulns --format cyclonedx --output sbom.cdx.json. You lose the raw inventory, but you can still refresh the CycloneDX file later.
  • Convert an SBOM you already have. scanoss-cli sbom also converts between CycloneDX and SPDX: scanoss-cli sbom bom.cdx.json --format spdx --output bom.spdx.json.
  • Run in a container. See Using Docker.