Skip to content

SBOM export ​

dagsec writes a CycloneDX 1.5 software bill of materials (SBOM) listing every package version your lockfiles pin, with the known vulnerabilities that affect them.

From the dashboard ​

Open a finished scan and click Download SBOM. The file is named after the repository, such as acme-web.cdx.json. Scans made before SBOM support need to be run again.

From the command line ​

sh
dagsec sbom [PATH] [-o FILE] [--name NAME]
OptionDefaultMeaning
PATH.Project directory
-o, --outputstdoutFile to write
--nameDirectory nameProject name recorded in the SBOM

dagsec sbom reads lockfiles only; it needs no git history and doesn't compute health scores. With -o it prints how many components and vulnerabilities it wrote.

Contents ​

  • metadata.component: your project, as an application.
  • metadata.tools: dagsec and its version.
  • components: one library per pinned package, with a package URL as its bom-ref. Direct dependencies without a lockfile are listed without a version.
  • vulnerabilities: each advisory with its ID, source (OSV), severity rating, description, recommendation ("Upgrade to X or later") and the components it affects.

Package URLs ​

Ecosystempurl
npmpkg:npm/%40babel/core@7.24.0
PyPIpkg:pypi/flask-login@0.6.3
crates.iopkg:cargo/serde@1.0.200
Gopkg:golang/github.com/gin-gonic/gin@v1.9.0
Mavenpkg:maven/org.apache.logging.log4j/log4j-core@2.14.1
NuGetpkg:nuget/Newtonsoft.Json@12.0.1

Severity maps to CycloneDX as critical, high, medium (dagsec's moderate), low and unknown.