sbom

por nvidia

Generar y gestionar Listas de Materiales de Software (SBOMs) para el proyecto OpenShell. Cubre la generación de SBOMs con Syft, resolución de licencias a través de registros públicos,…

npx skills add https://github.com/nvidia/openshell --skill sbom

SBOM Generation and License Resolution

Generate CycloneDX SBOMs, resolve missing licenses, and export to CSV for compliance review.

Overview

The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft, resolves missing or hash-based licenses by querying public registries (crates.io, npm, PyPI), and exports the results to CSV for stakeholder review.

SBOMs are release artifacts only -- they are generated on demand and not committed to the repository. Output lands in deploy/sbom/output/ (gitignored).

Release Dev and Release Tag image builds separately embed cargo-auditable metadata in the staged gateway and supervisor binaries. This metadata describes the binary's Rust dependency graph and lets Syft discover Cargo packages from the binary itself. It is not a complete image SBOM and is not an OCI SBOM attestation; publishing such an attestation remains separate work.

Prerequisites

  • mise install has been run (installs Syft and other tools)
  • The repository is checked out at the root

Inspecting an Auditable Image Binary

Opt into auditable metadata when staging a local image binary:

OPENSHELL_AUDITABLE=1 PREBUILT_ARCH=amd64 \
  tasks/scripts/stage-prebuilt-binaries.sh gateway

Scan the staged binary rather than the source tree:

mise x -- syft \
  "file:deploy/docker/.build/prebuilt-binaries/amd64/openshell-gateway" \
  -o cyclonedx-json

This output is limited to packages Syft discovers from that binary. Use mise run sbom for the broader source-tree license-compliance inventory.

Workflow 1: Full SBOM Generation (One Command)

mise run sbom

This single command chains three stages:

  1. Generate (sbom:generate): Syft scans the workspace source tree and produces a CycloneDX JSON SBOM
  2. Resolve (sbom:resolve): Public registry APIs fill in missing or hash-based licenses in the JSON
  3. CSV (sbom:csv): JSON SBOMs are converted to CSV for review

Output directory: deploy/sbom/output/

After running, the user can find:

  • deploy/sbom/output/*.cdx.json -- full CycloneDX SBOMs
  • deploy/sbom/output/*.csv -- CSV exports ready for spreadsheet review

Workflow 2: Individual Stages

Run stages independently when debugging or iterating:

mise run sbom:generate   # Generate JSON SBOMs only (requires Syft)
mise run sbom:resolve    # Resolve licenses in existing JSONs (queries APIs)
mise run sbom:csv        # Convert existing JSONs to CSV

Workflow 3: License Check (CI Advisory)

mise run sbom:check

Reports unresolved licenses without failing. Intended for PR CI as a non-blocking advisory check. Requires that SBOMs have already been generated (mise run sbom:generate).

Workflow 4: Processing External SBOMs

The Python scripts accept explicit file paths, so they can process SBOMs from any source (e.g., NVIDIA nSpect pipeline output):

uv run python deploy/sbom/resolve_licenses.py /path/to/external-sbom.json
uv run python deploy/sbom/sbom_to_csv.py /path/to/external-sbom.json

License Resolution Details

The resolver queries these public registries:

RegistryPackage URL prefixMethod
crates.iopkg:cargo/*REST API
npmpkg:npm/*Registry API
PyPIpkg:pypi/*JSON API
Go modulespkg:golang/*Known license map (no API)
Debian/Ubuntupkg:deb/*Known license map

Components from private registries (e.g., @openclaw/* npm packages) are not resolved and will appear in the "unresolved" report.

Output Files

PatternDescription
deploy/sbom/output/openshell-source-{version}.cdx.jsonCycloneDX JSON SBOM
deploy/sbom/output/openshell-source-{version}.csvCSV export (name, version, type, purl, licenses, bom-ref)

Key Files

FilePurpose
deploy/sbom/resolve_licenses.pyLicense resolution script
deploy/sbom/sbom_to_csv.pyJSON-to-CSV converter
tasks/sbom.tomlMise task definitions
mise.tomlSyft tool definition (under [tools])

Quick Reference

TaskCommand
Full pipelinemise run sbom
Generate onlymise run sbom:generate
Resolve licensesmise run sbom:resolve
Export CSVmise run sbom:csv
CI license checkmise run sbom:check
Process external SBOMuv run python deploy/sbom/resolve_licenses.py <file>

Más skills de nvidia

compileiq-debug
nvidia
Úsalo cuando algo esté mal: Search() se cuelga, todas las evaluaciones devuelven INVALID_SCORE, las puntuaciones no mejoran, cada configuración devuelve el mismo número, errores de ptxas…
create-github-pr
nvidia
Crear solicitudes de extracción de GitHub usando la CLI gh. Usar cuando el usuario quiera crear un nuevo PR, enviar código para revisión o abrir una solicitud de extracción. Palabras clave de activación -…
nemoclaw-maintainer-cross-issue-sweep
nvidia
Escanea otros issues abiertos para encontrar aquellos que un PR dado también podría corregir o romper accidentalmente. Genera oportunidades de corrección adyacente y riesgos de contradicción con archivo:línea…
fhir-basics
nvidia
Enseña a los agentes cómo funcionan las APIs de FHIR R4, qué recursos están disponibles, cómo consultarlos con parámetros de búsqueda y cómo analizar correctamente todos los formatos de respuesta…
compileiq-validate-result
nvidia
Usar DESPUÉS de que una Búsqueda haya finalizado y ANTES de reclamar cualquier aceleración o enviar un ACF. Carga el CSV de dump_results, extrae los mejores K candidatos (de un solo objetivo)…
changelog-audit
nvidia
Auditar el CHANGELOG.md de Warp antes de un lanzamiento: recuperar entradas perdidas, ordenar por impacto en el usuario, refinar el lenguaje de las entradas, ajustar saltos de línea y (en modo rama de lanzamiento) incrementar comparación…
maintain-dynamic-plugins
nvidia
Mantener los cargadores de plugins dinámicos de NeMo Relay, manifiestos, SDKs nativos de Rust, protocolo de trabajador gRPC, SDK de trabajador Python, documentación, pruebas y cobertura del flujo de trabajo de lanzamiento
dgx-diagnose
nvidia
Diagnostica problemas comunes de la DGX Station GB300: fallos de CUDA, direccionamiento incorrecto de GPU, errores de contenedores vLLM/SGLang, problemas de estado MIG, errores de NVLink/Fabric Manager,…