Goal
For every release, publish a Software Bill of Materials (SBOM) in both common formats:- CycloneDX 1.7, with components, licences, evidence, and known vulnerabilities
- SPDX 2.3, with components and licences
When to use it
- A customer, a regulation, or your own policy asks for an SBOM with each release.
- You want a single record of what a release contained, stored next to the release.
Prerequisites
- scanoss-cli,
jq, andSCANOSS_API_KEY(see Recipes) - The source tree checked out at the release tag
- Optional: a
scanoss.jsonwith your approvals, so the SBOM marks approved components
The script
Save this asci/scanoss-release-sbom.sh and run it from the repository root in your release
job.
What each step does
- Scan once.
scan .fingerprints the release, matches it against the SCANOSS Knowledge Base, and writes the raw inventory.--includeadds three layers:deps: dependencies declared in manifest files such aspackage.jsonorgo.mod, resolved through the API. They appear with"scope": "declared".licenses: the licences of every component, detected or declared.vulns: known vulnerabilities for every component.
- Convert.
scanoss-cli sbomreads the inventory and writes the requested format. It does not contact the API, so it is fast and gives the same result each time.--formatis required. - Check.
jq -eexits non-zero if a file is not the expected format, so the job stops before it publishes a broken SBOM. - Checksums. A
SHA256SUMSfile lets consumers confirm they have the files you published.
sbom/ to the release, or upload them to wherever you store release
artefacts.
What the output means
What each format can hold differs:
A component that is both detected in your code and declared in a manifest appears once. Components
approved in
scanoss.json carry the scanoss:identified property in CycloneDX.
How it fails the pipeline
The script usesset -euo pipefail, so it stops at the first failing command:
An SBOM documents what a release contains. It does not decide whether the release is allowed. To
block a release on licences or vulnerabilities, run the
licence and vulnerability gate
on
inventory-<version>.json before you publish:
Variations
- One format only. Skip the raw inventory and scan straight into a format:
scanoss-cli scan . --include deps,licenses,vulns --format cyclonedx --output sbom.cdx.json. You lose the raw inventory, but you can still refresh the CycloneDX file later. - Convert an SBOM you already have.
scanoss-cli sbomalso converts between CycloneDX and SPDX:scanoss-cli sbom bom.cdx.json --format spdx --output bom.spdx.json. - Run in a container. See Using Docker.