sbom

oleh nvidia

Buat dan kelola Software Bill of Materials (SBOM) untuk proyek OpenShell. Mencakup pembuatan SBOM dengan Syft, resolusi lisensi melalui registri publik,…

npx skills add https://github.com/nvidia/openshell --skill sbom

SBOM Generation and License Resolution

Generate CycloneDX SBOMs, resolve missing licenses, and export to CSV for compliance review.

Overview

The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft, resolves missing or hash-based licenses by querying public registries (crates.io, npm, PyPI), and exports the results to CSV for stakeholder review.

SBOMs are release artifacts only -- they are generated on demand and not committed to the repository. Output lands in deploy/sbom/output/ (gitignored).

Release Dev and Release Tag image builds separately embed cargo-auditable metadata in the staged gateway and supervisor binaries. This metadata describes the binary's Rust dependency graph and lets Syft discover Cargo packages from the binary itself. It is not a complete image SBOM and is not an OCI SBOM attestation; publishing such an attestation remains separate work.

Prerequisites

  • mise install has been run (installs Syft and other tools)
  • The repository is checked out at the root

Inspecting an Auditable Image Binary

Opt into auditable metadata when staging a local image binary:

OPENSHELL_AUDITABLE=1 PREBUILT_ARCH=amd64 \
  tasks/scripts/stage-prebuilt-binaries.sh gateway

Scan the staged binary rather than the source tree:

mise x -- syft \
  "file:deploy/docker/.build/prebuilt-binaries/amd64/openshell-gateway" \
  -o cyclonedx-json

This output is limited to packages Syft discovers from that binary. Use mise run sbom for the broader source-tree license-compliance inventory.

Workflow 1: Full SBOM Generation (One Command)

mise run sbom

This single command chains three stages:

  1. Generate (sbom:generate): Syft scans the workspace source tree and produces a CycloneDX JSON SBOM
  2. Resolve (sbom:resolve): Public registry APIs fill in missing or hash-based licenses in the JSON
  3. CSV (sbom:csv): JSON SBOMs are converted to CSV for review

Output directory: deploy/sbom/output/

After running, the user can find:

  • deploy/sbom/output/*.cdx.json -- full CycloneDX SBOMs
  • deploy/sbom/output/*.csv -- CSV exports ready for spreadsheet review

Workflow 2: Individual Stages

Run stages independently when debugging or iterating:

mise run sbom:generate   # Generate JSON SBOMs only (requires Syft)
mise run sbom:resolve    # Resolve licenses in existing JSONs (queries APIs)
mise run sbom:csv        # Convert existing JSONs to CSV

Workflow 3: License Check (CI Advisory)

mise run sbom:check

Reports unresolved licenses without failing. Intended for PR CI as a non-blocking advisory check. Requires that SBOMs have already been generated (mise run sbom:generate).

Workflow 4: Processing External SBOMs

The Python scripts accept explicit file paths, so they can process SBOMs from any source (e.g., NVIDIA nSpect pipeline output):

uv run python deploy/sbom/resolve_licenses.py /path/to/external-sbom.json
uv run python deploy/sbom/sbom_to_csv.py /path/to/external-sbom.json

License Resolution Details

The resolver queries these public registries:

RegistryPackage URL prefixMethod
crates.iopkg:cargo/*REST API
npmpkg:npm/*Registry API
PyPIpkg:pypi/*JSON API
Go modulespkg:golang/*Known license map (no API)
Debian/Ubuntupkg:deb/*Known license map

Components from private registries (e.g., @openclaw/* npm packages) are not resolved and will appear in the "unresolved" report.

Output Files

PatternDescription
deploy/sbom/output/openshell-source-{version}.cdx.jsonCycloneDX JSON SBOM
deploy/sbom/output/openshell-source-{version}.csvCSV export (name, version, type, purl, licenses, bom-ref)

Key Files

FilePurpose
deploy/sbom/resolve_licenses.pyLicense resolution script
deploy/sbom/sbom_to_csv.pyJSON-to-CSV converter
tasks/sbom.tomlMise task definitions
mise.tomlSyft tool definition (under [tools])

Quick Reference

TaskCommand
Full pipelinemise run sbom
Generate onlymise run sbom:generate
Resolve licensesmise run sbom:resolve
Export CSVmise run sbom:csv
CI license checkmise run sbom:check
Process external SBOMuv run python deploy/sbom/resolve_licenses.py <file>

Lebih banyak skill dari nvidia

compileiq-debug
nvidia
Gunakan ketika ada yang salah: Search() menggantung, semua evaluasi mengembalikan INVALID_SCORE, skor tidak kunjung membaik, setiap konfigurasi mengembalikan angka yang sama, error ptxas…
create-github-pr
nvidia
Buat pull request GitHub menggunakan gh CLI. Gunakan saat pengguna ingin membuat PR baru, mengirimkan kode untuk ditinjau, atau membuka pull request. Kata kunci pemicu -…
nemoclaw-maintainer-cross-issue-sweep
nvidia
Memindai isu terbuka lainnya untuk menemukan isu yang mungkin juga diperbaiki atau secara tidak sengaja dirusak oleh suatu PR tertentu. Menghasilkan peluang perbaikan yang berdekatan dan risiko kontradiksi dengan file:baris…
fhir-basics
nvidia
Mengajarkan agen cara kerja API FHIR R4, sumber daya apa saja yang tersedia, cara melakukan kueri dengan parameter pencarian, dan cara mengurai semua format respons dengan benar…
compileiq-validate-result
nvidia
Gunakan SETELAH Pencarian selesai dan SEBELUM mengklaim percepatan atau mengirim ACF. Muat CSV dump_results, ekstrak kandidat top-K (tujuan tunggal)…
changelog-audit
nvidia
Audit Warp CHANGELOG.md sebelum rilis: pulihkan entri yang hilang, urutkan berdasarkan dampak pengguna, perbaiki bahasa entri, bungkus baris, dan (mode cabang rilis) naikkan bandingkan…
maintain-dynamic-plugins
nvidia
Mempertahankan pemuat plugin dinamis NeMo Relay, manifes, SDK asli Rust, protokol pekerja gRPC, SDK pekerja Python, dokumen, pengujian, dan cakupan alur kerja rilis
dgx-diagnose
nvidia
Diagnosis masalah umum DGX Station GB300 — crash CUDA, penargetan GPU yang salah, bug kontainer vLLM/SGLang, masalah status MIG, kesalahan NVLink/Fabric Manager,…