Generate a CycloneDX SBOM
This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.
Use kix compliance sbom to produce a CycloneDX 1.6 software bill of
materials from a rendered cluster. The command evaluates the cluster locally
and does not need Kubernetes access.
Generate the SBOM
Section titled “Generate the SBOM”Pass the cluster name and redirect stdout to a file:
❱ kix compliance sbom 19-scorecards > sbom.json The output is JSON by default. This captured excerpt shows the document type, cluster component, component counts, and dependency count:
❱ kix compliance sbom 19-scorecards Show output
{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"metadata": {
"component": {
"bom-ref": "cluster-19-scorecards",
"description": "kix cluster 19-scorecards",
"name": "cluster-19-scorecards",
"properties": [
{
"name": "kix:activation-hash",
"value": "a3k1lgi8qq6cniircdpphwc2bc8gj5a4"
},
{
"name": "kix:flake-ref",
"value": "kix-examples"
}
],
"type": "platform",
"version": "activation-a3k1lgi8qq6cniircdpphwc2bc8gj5a4"
}
},
"componentTypes": [
{
"type": "application",
"count": 5
},
{
"type": "container",
"count": 2
},
{
"type": "library",
"count": 3
}
],
"dependencyCount": 6
}
Building cluster '19-scorecards'...
Evaluating cluster '19-scorecards'...
Reading package index...
Loading store graph...
Reading 5 packages...
Discovering cluster-level resources...
Computing cross-package dependencies... The complete file contains:
- One
platformcomponent for the cluster. - One
applicationcomponent for each package instance. - One deduplicated
containercomponent for each image reference. - One
librarycomponent for each locked flake input. - Dependency edges between the cluster, packages, images, and inputs.
An image component includes a SHA-256 hash when its rendered reference has an
@sha256: digest.
Verify the file
Section titled “Verify the file”Check that the command produced a CycloneDX 1.6 document:
❱ jq -e '.bomFormat == "CycloneDX" and .specVersion == "1.6"' sbom.json The capture pipeline runs this same assertion on every regeneration, so a change to the emitted CycloneDX version fails the docs build rather than reaching you as a surprise.
Use --output yaml if the receiving system expects YAML:
❱ kix --output yaml compliance sbom 19-scorecards > sbom.yaml