Skip to content

Latest commit

History

67 Commits

Folders and files

NameName
Last commit message
Last commit date

sbomify SBOM Library

A collection of Software Bill of Materials (SBOMs) for popular open-source projects, automatically extracted and uploaded to sbomify for public browsing.

Overview

This repository manages SBOM extraction from multiple sources:

  • Docker OCI Attestations - Extract SBOMs embedded in Docker images via BuildKit attestations
  • Chainguard Images - Download signed SBOM attestations from Chainguard images via cosign
  • GitHub Releases - Download SBOMs published as release assets
  • Lockfile Sources - Download lockfiles for SBOM generation by sbomify

Each app has its own folder with version tracking. When you bump the version in config.yaml, only that app's SBOM is rebuilt and uploaded - not the entire repository.

Note: Each version only needs to be processed once. Once an SBOM is uploaded to sbomify, it is permanently stored there. There is no need to re-process the same version.

Projects

Each SBOM is discoverable via the Transparency Exchange API (TEA) using the TEI identifiers listed below.

Operating Systems

ProjectSourceTEIJob
Alpine LinuxDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/alpineSBOM
Amazon LinuxDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/amazonlinuxSBOM
DebianDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/debianSBOM
FedoraDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/fedoraSBOM
Oracle LinuxDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/oraclelinuxSBOM
Rocky LinuxDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/rockylinuxSBOM
UbuntuDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/ubuntuSBOM

Languages & Runtimes

ProjectSourceTEIJob
Eclipse TemurinDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/eclipse-temurinSBOM
ElixirDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/elixirSBOM
ErlangDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/erlangSBOM
GoDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/golangSBOM
Haskell (GHC)Dockerurn:tei:purl:library.sbomify.com:pkg:docker/library/haskellSBOM
JuliaDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/juliaSBOM
Node.jsDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/nodeSBOM
PerlDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/perlSBOM
PHPDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/phpSBOM
PythonDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/pythonSBOM
RDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/r-baseSBOM
RubyDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/rubySBOM
RustDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/rustSBOM
SwiftDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/swiftSBOM

Databases

ProjectSourceTEIJob
Apache CassandraDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/cassandraSBOM
InfluxDBDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/influxdbSBOM
MariaDBDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/mariadbSBOM
MemcachedDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/memcachedSBOM
MongoDBDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/mongoSBOM
Mongo ExpressDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/mongo-expressSBOM
MySQLDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/mysqlSBOM
Neo4jDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/neo4jSBOM
PostgreSQLDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/postgresSBOM
RedisDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/redisSBOM
Apache SolrDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/solrSBOM

Web & Application Servers

ProjectSourceTEIJob
Apache HTTP ServerDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/httpdSBOM
Apache TomcatDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/tomcatSBOM
CaddyGitHub Releaseurn:tei:purl:library.sbomify.com:pkg:github/caddyserver/caddySBOM
HAProxyDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/haproxySBOM
Kong GatewayDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/kongSBOM
NginxChainguardurn:tei:purl:library.sbomify.com:pkg:oci/cgr.dev/chainguard/nginxSBOM
TraefikDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/traefikSBOM

Applications & Platforms

ProjectSourceTEIJob
DrupalDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/drupalSBOM
GhostDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/ghostSBOM
KeycloakLockfileurn:tei:purl:library.sbomify.com:pkg:github/keycloak/keycloakSBOM
Keycloak JSLockfileurn:tei:purl:library.sbomify.com:pkg:github/keycloak/keycloakSBOM
SonarQubeDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/sonarqubeSBOM
WordPressDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/wordpressSBOM

Build Tools

ProjectSourceTEIJob
GradleDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/gradleSBOM
Apache MavenDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/mavenSBOM

Infrastructure & Messaging

ProjectSourceTEIJob
BashDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/bashSBOM
Docker RegistryDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/registrySBOM
Eclipse MosquittoDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/eclipse-mosquittoSBOM
RabbitMQDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/rabbitmqSBOM
TelegrafDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/telegrafSBOM
Apache ZooKeeperDockerurn:tei:purl:library.sbomify.com:pkg:docker/library/zookeeperSBOM

Security & SBOM Tools

ProjectSourceTEIJob
Dependency TrackGitHub Releaseurn:tei:purl:library.sbomify.com:pkg:github/DependencyTrack/dependency-trackSBOM
Dependency Track FrontendGitHub Releaseurn:tei:purl:library.sbomify.com:pkg:github/DependencyTrack/frontendSBOM
OSV ScannerLockfileurn:tei:purl:library.sbomify.com:pkg:github/google/osv-scannerSBOM
SyftLockfileurn:tei:purl:library.sbomify.com:pkg:github/anchore/syftSBOM
TrivyGitHub Releaseurn:tei:purl:library.sbomify.com:pkg:github/aquasecurity/trivySBOM

Directory Structure

.
├── .github/
│ └── workflows/
│ ├── sbom-builder.yml # Reusable workflow (main logic)
│ ├── _sbom-template.yml # Template for new app workflows
│ └── sbom-<app-name>.yml # Per-app workflow
├── apps/
│ └── <app-name>/ # Example app
│ └── config.yaml # App configuration (includes version)
├── scripts/
│ ├── fetch-sbom.sh # Main entry point
│ ├── check-updates.sh # Check for upstream version updates
│ ├── lib/
│ │ └── common.sh # Shared utilities
│ └── sources/
│ ├── docker-attestation.sh # Docker extraction
│ ├── github-release.sh # GitHub release download
│ └── lockfile-generator.sh # Lockfile download
└── README.md

Quick Start

Adding a New App

  1. Create the app folder:

    mkdir -p apps/myapp
  2. Create apps/myapp/config.yaml:

    name: myappversion: "1.0.0"# Must be valid semverformat: cyclonedx # or spdxsource:
    type: docker # or github_release, lockfile, chainguardimage: "library/myapp"registry: "docker.io"sbomify:
    component_id: "your-component-id"component_name: "My App"

    Valid version formats: 1.2.3, 1.2.3-rc1, 1.2.3-alpha.1+build. Note:latest is not allowed.

  3. Create the workflow file:

    cp .github/workflows/_sbom-template.yml .github/workflows/sbom-myapp.yml
    # Edit the file and replace 'example-app' with 'myapp'
  4. Commit and push:

    git add apps/myapp .github/workflows/sbom-myapp.yml
    git commit -m "Add myapp SBOM"
    git push

Bumping a Version

Simply update the version field in config.yaml:

# apps/nginx/config.yamlname: nginxversion: "1.26.0"# Update this line
...
git add apps/nginx/config.yaml
git commit -m "Bump nginx to 1.26.0"
git push

The GitHub Action will automatically rebuild and upload only the nginx SBOM.

Configuration Reference

App Configuration (config.yaml)

# Required: App name (should match folder name)name: nginx# Required: Version (must be valid semver)version: "1.25.4"# Required: SBOM formatformat: cyclonedx # cyclonedx | spdx# Required: Source configurationsource:
type: docker # docker | github_release | lockfile | chainguard# ... source-specific options (see below)# Required for upload: sbomify configurationsbomify:
component_id: "abc123-def456"component_name: "Nginx"

Source Types

Docker OCI Attestations

Extract SBOMs from Docker image attestations (requires images built with BuildKit SBOM support):

source:
type: dockerimage: "library/nginx"# Image name (required)registry: "docker.io"# Registry (default: docker.io)platform: "linux/amd64"# Platform (default: linux/amd64)

Chainguard Images

Download signed SBOM attestations from Chainguard images using cosign:

source:
type: chainguardimage: "nginx"# Chainguard image name (required)registry: "cgr.dev/chainguard"# Registry (default: cgr.dev/chainguard)platform: "linux/amd64"# Platform (default: linux/amd64)

Note: Chainguard images use SPDX format by default. Set format: spdx in your config.

GitHub Release

Download SBOMs from GitHub release assets:

source:
type: github_releaserepo: "owner/repo"# GitHub repository (required)asset: "bom.json"# Asset filename (required, supports ${version})tag_prefix: "v"# Tag prefix (default: "")tag_suffix: ""# Tag suffix (default: "")

The asset field supports ${version} substitution for projects that include the version in the asset filename:

source:
type: github_releaserepo: "caddyserver/caddy"asset: "caddy_${version}_linux_amd64.sbom"# Becomes caddy_2.10.1_linux_amd64.sbomtag_prefix: "v"

Lockfile Sources

Download lockfiles for SBOM generation by the sbomify GitHub Action:

source:
type: lockfilerepo: "owner/repo"# GitHub repository (required)lockfile: "package-lock.json"# Path to lockfile (required)tag_prefix: "v"# Tag prefixclone: false # Shallow clone repo instead of downloading lockfile

For projects with complex dependency structures (e.g., Maven multi-module projects), set clone: true to perform a shallow clone of the entire repository:

source:
type: lockfilerepo: "keycloak/keycloak"lockfile: "pom.xml"clone: true # Clone repo for full dependency resolution

Note: SBOM generation from lockfiles is handled automatically by the sbomify GitHub Action.

Local Development

Prerequisites

  • bash 4.0+
  • jq - JSON processor
  • yq - YAML processor

For Docker sources:

  • docker with buildx, or
  • crane (from go-containerregistry), or
  • oras

For Chainguard sources:

  • cosign (from sigstore)

For lockfile sources:

  • No additional tools required (SBOM generation handled by sbomify GitHub Action)

Running Locally

# Fetch SBOM for an app
./scripts/fetch-sbom.sh nginx
# Fetch with verbose output
./scripts/fetch-sbom.sh nginx --verbose
# Dry-run mode (no actual fetching)
./scripts/fetch-sbom.sh nginx --dry-run

Checking for Updates

# Check all apps for upstream version updates
./scripts/check-updates.sh
# Only check specific source type
./scripts/check-updates.sh --type docker
# Check specific apps
./scripts/check-updates.sh --app redis,trivy
# Auto-update config.yaml files
./scripts/check-updates.sh --update
# Preview updates without writing
./scripts/check-updates.sh --update --dry-run
# JSON output (for CI)
./scripts/check-updates.sh --json

Environment Variables

VariableDescriptionDefault
LOG_LEVELLogging level: DEBUG, INFO, WARN, ERRORINFO
DRY_RUNRun in dry-run modefalse
SBOMIFY_TOKENsbomify API token for upload-
GH_TOKENGitHub token for API access-

GitHub Actions

Secrets

Configure these secrets in your repository:

SecretDescriptionRequired
SBOMIFY_TOKENsbomify API token for uploading SBOMsFor upload

Manual Trigger

Each app workflow can be manually triggered from the Actions tab with optional dry-run mode.

Workflow Structure

  • Per-app workflows (sbom-<app-name>.yml) - Thin wrappers that trigger on config.yaml changes
  • Reusable workflow (sbom-builder.yml) - Contains all the build logic
  • Template (_sbom-template.yml) - Copy this to create new app workflows

This design ensures:

  1. Only the changed app is rebuilt (via path filters on config.yaml)
  2. Build logic is centralized and maintainable
  3. New apps just need a simple workflow file

Contributing

  1. Fork the repository
  2. Add your app following the Quick Start guide
  3. Test locally with ./scripts/fetch-sbom.sh <app-name>
  4. Submit a pull request

License

See LICENSE for details.

About

sbomify's SBOM Library

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages