bomctl/bomctl

By bomctl

Updated about 1 year ago

Format-agnostic SBOM tooling, which bridges the gap between SBOM generation and SBOM analysis.

Image
Security
0

1.5K

bomctl/bomctl repository overview

bomctl

OpenSSF Scorecard Go Report Card Go Reference Slack

bomctl is format-agnostic Software Bill of Materials (SBOM) tooling, which is intended to bridge the gap between SBOM generation and SBOM analysis tools. It focuses on supporting more complex SBOM operations by being opinionated on only supporting the NTIA minimum fields or other fields supported by protobom.

Note

This is an experimental project under active development. We'd love feedback on the concept, scope, and architecture!

Features

  • Work with multiple SBOMs in tree structures (through external references)
  • Fetch and push SBOMs using HTTPS, OCI, and GIT protocols
  • Leverage a .netrc file to handle authentication
  • Manipulate SBOMs with commands like diff, split, and redact
  • Manage SBOMs using a persistent database cache
  • Interface with OpenSSF projects and services like GUAC and Sigstore

Join our Community

Tag summary

Content type

Image

Digest

sha256:8e4629cee

Size

980 Bytes

Last updated

about 1 year ago

docker pull bomctl/bomctl:sha256-4a98f707fefbb66d5401ab7c17c9f1d4266d9a3cbecb465a0fa461e08f6fb0e0.sig