Open source · Compliance

DSI SBOM CLI Apache-2.0

Generates CycloneDX and SPDX SBOMs from a container image or a lockfile, with a diff mode for release gates.

Browse the catalogue

Public repository

https://github.com/dev-sec-it/sbom-cli

View repository

Releases, issues and the commit history are on the repository, so the license and the maintenance status can be checked against the last tagged release rather than taken on trust.

Catalogue record

The facts a buyer screens on first

Every value below is copied from the catalogue entry and is verifiable against the public repository.

License
Apache-2.0

OSI identifier, as published in the repository.

Stack
Go

Primary language and runtime.

Status
Production

As recorded in the DEV SEC IT catalogue.

Stars
760

Counted from the public repository at the time of writing.

What we maintain

Our contribution to DSI SBOM CLI

This project is on the catalogue because we own part of it. The parts we wrote, review and release are named here; everything else is upstream work we depend on.

Maintenance

Maintained by DEV SEC IT

What we wrote

CycloneDX writer and the CI diff gate

First tagged release

First tagged release in 2024.

Where it runs

An internal dependency, not a side project.

DSI SBOM CLI is consumed inside DEV SEC IT's own platforms, which is why its release cadence and license are kept current rather than left to a final commit.

  • Consumed in production

    dCloud (Self-host or managed), dDrive (Self-host or managed).

Talk to us

Need this running inside your own perimeter?

We maintain this project and the platforms built on it. If you want a deployment, a review or a fix against your environment, the same engineers who ship it can scope it.

All open source