How to create an SBOM
Tools and commands for creating an SBOM from source code or a container
An SBOM is created by a tool that goes through a project and lists the components it finds. Several open-source tools do this from the command line, and they run both on a developer's machine and in a build pipeline.
Open-source tools
| Tool | From | Reads |
|---|---|---|
| Syft | Anchore | Directories, container images, archives |
| Trivy | Aqua | Directories, container images, repositories |
| cdxgen | CycloneDX | Source code in many languages and build systems |
| Observer CLI | Bytesafe | Directories and container images |
Examples
Create an SBOM in CycloneDX format from the current directory:
syft dir:. -o cyclonedx-json=sbom.cdx.jsontrivy fs --format cyclonedx --output sbom.cdx.json .observer fs -o sbom.cdx.json .Create an SBOM from a container image:
syft nginx:latest -o cyclonedx-json=sbom.cdx.jsonWhere in the process
Create the SBOM in the build, not afterwards. An SBOM created when the dependencies are installed and locked contains the versions that are actually shipped, including transitive dependencies. Add the command as a step in the pipeline and store the file with the release.
Different types of SBOMs describes the difference between an SBOM from source, from the build and from a finished artefact. SBOM and DevOps describes how to build it into a pipeline.
Review the result
Different tools give different results for the same project. Check that the SBOM contains what you expect:
- Are all ecosystems in the project included, for example both npm and Python?
- Do the components have versions and unique identifiers (purl)?
- Are the transitive dependencies included, and the relationships between components?
Why is SBOM quality important? goes through common gaps.
Analyse an SBOM
The tools above can often also compare an SBOM against known vulnerabilities. Grype and osv-scanner are two tools made for exactly that.
For a quick overview without installing anything, there is the web tool SBOM Analyzer from Bytesafe. It is free and shows the number of components, known vulnerabilities, licences and whether the SBOM meets the SBOM Minimum Elements.