sbom

von nvidia

Erstellen und Verwalten von Software-Stücklisten (SBOMs) für das OpenShell-Projekt. Umfasst die SBOM-Erstellung mit Syft, die Lizenzauflösung über öffentliche Registries, …

npx skills add https://github.com/nvidia/openshell --skill sbom

SBOM Generation and License Resolution

Generate CycloneDX SBOMs, resolve missing licenses, and export to CSV for compliance review.

Overview

The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft, resolves missing or hash-based licenses by querying public registries (crates.io, npm, PyPI), and exports the results to CSV for stakeholder review.

SBOMs are release artifacts only -- they are generated on demand and not committed to the repository. Output lands in deploy/sbom/output/ (gitignored).

Release Dev and Release Tag image builds separately embed cargo-auditable metadata in the staged gateway and supervisor binaries. This metadata describes the binary's Rust dependency graph and lets Syft discover Cargo packages from the binary itself. It is not a complete image SBOM and is not an OCI SBOM attestation; publishing such an attestation remains separate work.

Prerequisites

  • mise install has been run (installs Syft and other tools)
  • The repository is checked out at the root

Inspecting an Auditable Image Binary

Opt into auditable metadata when staging a local image binary:

OPENSHELL_AUDITABLE=1 PREBUILT_ARCH=amd64 \
  tasks/scripts/stage-prebuilt-binaries.sh gateway

Scan the staged binary rather than the source tree:

mise x -- syft \
  "file:deploy/docker/.build/prebuilt-binaries/amd64/openshell-gateway" \
  -o cyclonedx-json

This output is limited to packages Syft discovers from that binary. Use mise run sbom for the broader source-tree license-compliance inventory.

Workflow 1: Full SBOM Generation (One Command)

mise run sbom

This single command chains three stages:

  1. Generate (sbom:generate): Syft scans the workspace source tree and produces a CycloneDX JSON SBOM
  2. Resolve (sbom:resolve): Public registry APIs fill in missing or hash-based licenses in the JSON
  3. CSV (sbom:csv): JSON SBOMs are converted to CSV for review

Output directory: deploy/sbom/output/

After running, the user can find:

  • deploy/sbom/output/*.cdx.json -- full CycloneDX SBOMs
  • deploy/sbom/output/*.csv -- CSV exports ready for spreadsheet review

Workflow 2: Individual Stages

Run stages independently when debugging or iterating:

mise run sbom:generate   # Generate JSON SBOMs only (requires Syft)
mise run sbom:resolve    # Resolve licenses in existing JSONs (queries APIs)
mise run sbom:csv        # Convert existing JSONs to CSV

Workflow 3: License Check (CI Advisory)

mise run sbom:check

Reports unresolved licenses without failing. Intended for PR CI as a non-blocking advisory check. Requires that SBOMs have already been generated (mise run sbom:generate).

Workflow 4: Processing External SBOMs

The Python scripts accept explicit file paths, so they can process SBOMs from any source (e.g., NVIDIA nSpect pipeline output):

uv run python deploy/sbom/resolve_licenses.py /path/to/external-sbom.json
uv run python deploy/sbom/sbom_to_csv.py /path/to/external-sbom.json

License Resolution Details

The resolver queries these public registries:

RegistryPackage URL prefixMethod
crates.iopkg:cargo/*REST API
npmpkg:npm/*Registry API
PyPIpkg:pypi/*JSON API
Go modulespkg:golang/*Known license map (no API)
Debian/Ubuntupkg:deb/*Known license map

Components from private registries (e.g., @openclaw/* npm packages) are not resolved and will appear in the "unresolved" report.

Output Files

PatternDescription
deploy/sbom/output/openshell-source-{version}.cdx.jsonCycloneDX JSON SBOM
deploy/sbom/output/openshell-source-{version}.csvCSV export (name, version, type, purl, licenses, bom-ref)

Key Files

FilePurpose
deploy/sbom/resolve_licenses.pyLicense resolution script
deploy/sbom/sbom_to_csv.pyJSON-to-CSV converter
tasks/sbom.tomlMise task definitions
mise.tomlSyft tool definition (under [tools])

Quick Reference

TaskCommand
Full pipelinemise run sbom
Generate onlymise run sbom:generate
Resolve licensesmise run sbom:resolve
Export CSVmise run sbom:csv
CI license checkmise run sbom:check
Process external SBOMuv run python deploy/sbom/resolve_licenses.py <file>

Mehr Skills von nvidia

compileiq-debug
nvidia
Verwenden, wenn etwas nicht stimmt: Search() hängt, alle Evaluierungen geben INVALID_SCORE zurück, Scores verbessern sich nicht, jede Konfiguration liefert dieselbe Zahl, ptxas-Fehler…
create-github-pr
nvidia
Erstelle GitHub-Pull-Requests mit der gh CLI. Verwende, wenn der Benutzer einen neuen PR erstellen, Code zur Überprüfung einreichen oder einen Pull-Request öffnen möchte. Auslöser-Schlüsselwörter -…
nemoclaw-maintainer-cross-issue-sweep
nvidia
Scannt andere offene Issues, um solche zu finden, die ein bestimmter PR möglicherweise ebenfalls behebt oder versehentlich kaputt macht. Gibt benachbarte Fix-Möglichkeiten und Widerspruchsrisiken mit Datei:Zeile… aus.
fhir-basics
nvidia
Bringt Agenten bei, wie FHIR R4 APIs funktionieren, welche Ressourcen verfügbar sind, wie man sie mit Suchparametern abfragt und wie man alle Antwortformate korrekt parst…
compileiq-validate-result
nvidia
Verwende NACH Abschluss einer Suche und VOR dem Einfordern eines Speedups oder dem Versand eines ACF. Lädt die dump_results CSV, extrahiert Top-K-Kandidaten (Einzelziel)...
changelog-audit
nvidia
Auditiere die CHANGELOG.md vor einem Release: stelle verlorene Einträge wieder her, sortiere nach Benutzerauswirkung, verfeinere die Sprache der Einträge, führe Zeilenumbrüche durch und (im Release-Branch-Modus) erhöhe die Vergleichsnummer…
maintain-dynamic-plugins
nvidia
Verwalte NeMo Relay dynamische Plugin-Lader, Manifeste, Rust native SDKs, gRPC Worker-Protokoll, Python Worker-SDK, Dokumentation, Tests und Abdeckung des Release-Workflows
dgx-diagnose
nvidia
Diagnostizieren Sie häufige DGX Station GB300-Probleme – CUDA-Abstürze, falsche GPU-Zuweisung, vLLM/SGLang-Container-Fehler, MIG-Status-Probleme, NVLink/Fabric-Manager-Fehler,…