SBOM export
dagsec writes a CycloneDX 1.5 software bill of materials (SBOM) listing every package version your lockfiles pin, with the known vulnerabilities that affect them.
From the dashboard
Open a finished scan and click Download SBOM. The file is named after the repository, such as acme-web.cdx.json. Scans made before SBOM support need to be run again.
From the command line
sh
dagsec sbom [PATH] [-o FILE] [--name NAME]| Option | Default | Meaning |
|---|---|---|
PATH | . | Project directory |
-o, --output | stdout | File to write |
--name | Directory name | Project name recorded in the SBOM |
dagsec sbom reads lockfiles only; it needs no git history and doesn't compute health scores. With -o it prints how many components and vulnerabilities it wrote.
Contents
metadata.component: your project, as an application.metadata.tools: dagsec and its version.components: onelibraryper pinned package, with a package URL as itsbom-ref. Direct dependencies without a lockfile are listed without a version.vulnerabilities: each advisory with its ID, source (OSV), severity rating, description, recommendation ("Upgrade to X or later") and the components itaffects.
Package URLs
| Ecosystem | purl |
|---|---|
| npm | pkg:npm/%40babel/core@7.24.0 |
| PyPI | pkg:pypi/flask-login@0.6.3 |
| crates.io | pkg:cargo/serde@1.0.200 |
| Go | pkg:golang/github.com/gin-gonic/gin@v1.9.0 |
| Maven | pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1 |
| NuGet | pkg:nuget/Newtonsoft.Json@12.0.1 |
Severity maps to CycloneDX as critical, high, medium (dagsec's moderate), low and unknown.