sbom
Installation
SKILL.md
SBOM Generation and License Resolution
Generate CycloneDX SBOMs, resolve missing licenses, and export to CSV for compliance review.
Overview
The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft, resolves missing or hash-based licenses by querying public registries (crates.io, npm, PyPI), and exports the results to CSV for stakeholder review.
SBOMs are release artifacts only -- they are generated on demand and not committed to the repository. Output lands in deploy/sbom/output/ (gitignored).
Pushed gateway and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.
Prerequisites
mise installhas been run (installs Syft and other tools)- The repository is checked out at the root