SBOM Guide
SBOM in practice

SBOM and DevOps

Create, check and store an SBOM in every build

An SBOM created by hand soon goes out of date. In a build pipeline it is created automatically for every version instead, by the same process that builds the software.

The steps in the pipeline

1. Create the SBOM in the build

Add a step that creates the SBOM after the dependencies have been installed. It then contains the versions that are actually included, transitive dependencies as well.

An example for GitHub Actions with Syft, which assumes that Syft is installed in the build:

- name: Create SBOM
  run: syft dir:. -o cyclonedx-json=sbom.cdx.json

- name: Store SBOM with the build
  uses: actions/upload-artifact@v4
  with:
    name: sbom
    path: sbom.cdx.json

The same principle applies in GitLab CI, Azure Pipelines and Jenkins. How to create an SBOM lists more tools.

2. Check it

Let the pipeline check the SBOM before the release moves on:

  • does it meet the SBOM Minimum Elements?
  • are there known vulnerabilities above a level you have decided?
  • are there licences that your policy does not allow?

Decide which deviations stop the build and which only give a warning. A rule that stops too much is soon switched off.

3. Store it with the release

The SBOM belongs to a specific version. Store it with the build output and upload it to the system where you collect SBOMs. For containers, the SBOM can also be attached to the image in the registry.

4. Monitor after delivery

New vulnerabilities are found in versions that have already shipped. The stored SBOMs therefore have to be compared against vulnerability data continuously, and someone has to be told when a version in use is affected. SBOM and vulnerability management describes the workflow.

Who does what

RoleResponsibility
Development teamThat the build creates an SBOM and that deviations in the pipeline are fixed
Security teamThe rules for what stops a build, and monitoring after delivery
Product ownerWhich versions are supported and for how long

Tools

Syft, Trivy and cdxgen create SBOMs. To collect them, check them against rules and monitor them, you need a system for SBOM management. SBOM Observer from Bytesafe, which runs this site, is one. Dependency-Track is an open-source alternative.

On this page