Skip to content

SBOM export ​

dagsec writes a CycloneDX 1.5 software bill of materials (SBOM) listing every package version your lockfiles pin, with the known vulnerabilities that affect them.

From the dashboard ​

Open a finished scan and click Download SBOM. The file is named after the repository, such as acme-web.cdx.json. Scans made before SBOM support need to be run again.

From the command line ​

sh
dagsec sbom [PATH] [-o FILE] [--name NAME]
OptionDefaultMeaning
PATH.Project directory
-o, --outputstdoutFile to write
--nameDirectory nameProject name recorded in the SBOM

dagsec sbom reads lockfiles only; it needs no git history and doesn't compute health scores. With -o it prints how many components and vulnerabilities it wrote.

Contents ​

  • metadata.component: your project, as an application.
  • metadata.tools: dagsec and its version.
  • components: one library per pinned package, with a package URL as its bom-ref. Direct dependencies without a lockfile are listed without a version.
  • vulnerabilities: each advisory with its ID, source (OSV), severity rating, description, recommendation ("Upgrade to X or later") and the components it affects.

Package URLs ​

Ecosystempurl
npmpkg:npm/%40babel/[email protected]
PyPIpkg:pypi/[email protected]
crates.iopkg:cargo/[email protected]
Gopkg:golang/github.com/gin-gonic/[email protected]
Mavenpkg:maven/org.apache.logging.log4j/[email protected]
NuGetpkg:nuget/[email protected]

Severity maps to CycloneDX as critical, high, medium (dagsec's moderate), low and unknown.