Skip to content

Generate a CycloneDX SBOM

This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.

Use kix compliance sbom to produce a CycloneDX 1.6 software bill of materials from a rendered cluster. The command evaluates the cluster locally and does not need Kubernetes access.

Pass the cluster name and redirect stdout to a file:

Run in kix-examples/
❱ kix compliance sbom 19-scorecards > sbom.json

The output is JSON by default. This captured excerpt shows the document type, cluster component, component counts, and dependency count:

Run in kix-examples/ Output excerpt
❱ kix compliance sbom 19-scorecards Show output
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "metadata": {
    "component": {
      "bom-ref": "cluster-19-scorecards",
      "description": "kix cluster 19-scorecards",
      "name": "cluster-19-scorecards",
      "properties": [
        {
          "name": "kix:activation-hash",
          "value": "a3k1lgi8qq6cniircdpphwc2bc8gj5a4"
        },
        {
          "name": "kix:flake-ref",
          "value": "kix-examples"
        }
      ],
      "type": "platform",
      "version": "activation-a3k1lgi8qq6cniircdpphwc2bc8gj5a4"
    }
  },
  "componentTypes": [
    {
      "type": "application",
      "count": 5
    },
    {
      "type": "container",
      "count": 2
    },
    {
      "type": "library",
      "count": 3
    }
  ],
  "dependencyCount": 6
}
Building cluster '19-scorecards'...
  Evaluating cluster '19-scorecards'...
  Reading package index...
  Loading store graph...
  Reading 5 packages...
  Discovering cluster-level resources...
  Computing cross-package dependencies...

The complete file contains:

  • One platform component for the cluster.
  • One application component for each package instance.
  • One deduplicated container component for each image reference.
  • One library component for each locked flake input.
  • Dependency edges between the cluster, packages, images, and inputs.

An image component includes a SHA-256 hash when its rendered reference has an @sha256: digest.

Check that the command produced a CycloneDX 1.6 document:

Run in kix-examples/
❱ jq -e '.bomFormat == "CycloneDX" and .specVersion == "1.6"' sbom.json

The capture pipeline runs this same assertion on every regeneration, so a change to the emitted CycloneDX version fails the docs build rather than reaching you as a surprise.

Use --output yaml if the receiving system expects YAML:

Run in kix-examples/
❱ kix --output yaml compliance sbom 19-scorecards > sbom.yaml