SBOM and DevOps
Create, check and store an SBOM in every build
An SBOM created by hand soon goes out of date. In a build pipeline it is created automatically for every version instead, by the same process that builds the software.
The steps in the pipeline
1. Create the SBOM in the build
Add a step that creates the SBOM after the dependencies have been installed. It then contains the versions that are actually included, transitive dependencies as well.
An example for GitHub Actions with Syft, which assumes that Syft is installed in the build:
- name: Create SBOM
run: syft dir:. -o cyclonedx-json=sbom.cdx.json
- name: Store SBOM with the build
uses: actions/upload-artifact@v4
with:
name: sbom
path: sbom.cdx.jsonThe same principle applies in GitLab CI, Azure Pipelines and Jenkins. How to create an SBOM lists more tools.
2. Check it
Let the pipeline check the SBOM before the release moves on:
- does it meet the SBOM Minimum Elements?
- are there known vulnerabilities above a level you have decided?
- are there licences that your policy does not allow?
Decide which deviations stop the build and which only give a warning. A rule that stops too much is soon switched off.
3. Store it with the release
The SBOM belongs to a specific version. Store it with the build output and upload it to the system where you collect SBOMs. For containers, the SBOM can also be attached to the image in the registry.
4. Monitor after delivery
New vulnerabilities are found in versions that have already shipped. The stored SBOMs therefore have to be compared against vulnerability data continuously, and someone has to be told when a version in use is affected. SBOM and vulnerability management describes the workflow.
Who does what
| Role | Responsibility |
|---|---|
| Development team | That the build creates an SBOM and that deviations in the pipeline are fixed |
| Security team | The rules for what stops a build, and monitoring after delivery |
| Product owner | Which versions are supported and for how long |
Tools
Syft, Trivy and cdxgen create SBOMs. To collect them, check them against rules and monitor them, you need a system for SBOM management. SBOM Observer from Bytesafe, which runs this site, is one. Dependency-Track is an open-source alternative.