Documentation
¶
Overview ¶
Command sbom writes a CycloneDX SBOM of a container image and what it was built with: the packages inside the built image (OS packages, the modules linked into Go executables, shipped node packages), the contents of the images the Dockerfile's build stages start from (excluded from the delivered artifact, but part of how it was produced), Go executables given directly, and the packages of a package-lock.json.
Click to show internal directories.
Click to hide internal directories.