mirror of
https://github.com/valitydev/rebar3_sbom.git
synced 2024-11-06 00:35:19 +00:00
Rebar3 plugin to generate CycloneDX SBoM
src | ||
.gitignore | ||
LICENSE | ||
README.md | ||
rebar.config | ||
rebar.lock |
rebar3_sbom
Generates a Software Bill-of-Materials (SBoM) in CycloneDX format
Use
Add rebar3_sbom to your rebar config, either in a project or globally in ~/.config/rebar3/rebar.config:
{plugins, [rebar3_sbom]}.
Then run the 'sbom' task on a project:
$ rebar3 sbom
===> Verifying dependencies...
===> CycloneDX SBoM written to bom.xml
The following command line options are supported:
-o, --output the full path to the SBoM output file [default: bom.xml]
-f, --force overwite existing files without prompting for confirmation
[default: false]
By default only dependencies in the 'default' profile are included. To generate an SBoM covering development environments specify the relevant profiles using 'as':
$ rebar3 as default,test,docs sbom -o dev_bom.xml