Skip to content
@bomctl

bomctl

Moe

OpenSSF Sandbox Badge

OpenSSF Scorecard Go Report Card Go Reference Slack

bomctl is format-agnostic Software Bill of Materials (SBOM) tooling, which is intended to bridge the gap between SBOM generation and SBOM analysis tools. It focuses on supporting more complex SBOM operations on multiple SBOM files that represent systems by being opinionated on only supporting the NTIA minimum fields or other fields supported by protobom.

Note

This is an experimental project under active development. We'd love feedback on the concept, scope, and architecture!

Features

  • Work with multiple SBOMs in tree structures (through external references)
  • Fetch and push SBOMs using multiple protocols
  • Leverage a .netrc file to handle authentication
  • Manage SBOMs using a persistent database cache
  • FUTURE - Manipulate SBOMs with commands like diff, split, and redact
  • FUTURE - Interface with OpenSSF projects and services like GUAC and Sigstore

Join our Community

Pinned Loading

  1. bomctl bomctl Public

    Format agnostic SBOM tooling

    Go 77 15

Repositories

Showing 5 of 5 repositories
  • bomctl Public

    Format agnostic SBOM tooling

    bomctl/bomctl’s past year of commit activity
    Go 77 Apache-2.0 15 16 (4 issues need help) 8 Updated Nov 4, 2024
  • bomctl-playground Public

    A Gitpod based playground to understand bomctl

    bomctl/bomctl-playground’s past year of commit activity
    1 Apache-2.0 0 0 2 Updated Oct 28, 2024
  • .github Public
    bomctl/.github’s past year of commit activity
    0 Apache-2.0 0 0 0 Updated Oct 8, 2024
  • homebrew-bomctl Public

    Homebrew formula for bomctl

    bomctl/homebrew-bomctl’s past year of commit activity
    Ruby 0 Apache-2.0 0 0 0 Updated Oct 8, 2024
  • tac Public Forked from ossf/tac

    bomctl - OpenSSF Project Application

    bomctl/tac’s past year of commit activity
    0 61 0 2 Updated Oct 8, 2024

Top languages

Loading…

Most used topics

Loading…