Using the CLI
Install the Observer CLI, generate an SBOM, analyze it, and upload it.
Observer CLI is a free, open-source command-line tool. It generates CycloneDX SBOMs from source code, container images, Kubernetes clusters, and builds; analyzes them for vulnerabilities and policy violations; and uploads them to SBOM Observer.
Generate, analyze, and upload an SBOM
Install
Download the archive for your platform (Linux, macOS, or Windows) from the Observer CLI releases page, unpack it, and put the observer binary on your PATH.
Generate your first SBOM
From source code:
observer fs -o my-sbom.cdx.json .From a container image:
observer image -o nginx.cdx.json nginx:latestAnalyze
Without a token, analyze sends the SBOM to a temporary namespace on SBOM Observer, which is deleted once the request is processed, and prints the vulnerabilities and policy violations it finds:
observer analyze my-sbom.cdx.jsonTo analyze against your own namespace's policies, create an access token and set it in OBSERVER_TOKEN. If the token's namespace isn't called default, also set OBSERVER_NAMESPACE to its name, the part of the app URL after /workspace/:
export OBSERVER_TOKEN=<token>
export OBSERVER_NAMESPACE=<namespace> # only if it isn't "default"
observer analyze my-sbom.cdx.jsonWith a token, --fail can also fail a build. See Enforce policies in CI/CD.
Verify (optional)
observer verify my-sbom.cdx.jsonThis checks that the SBOM is well-formed CycloneDX before upload, and with --artifacts compares it against built files.
Upload
Uploading needs the same two variables. The SBOM goes to the namespace in OBSERVER_NAMESPACE (default if unset), which must be the namespace the token was created in:
export OBSERVER_TOKEN=<token>
export OBSERVER_NAMESPACE=<namespace> # only if it isn't "default"
observer upload my-sbom.cdx.jsonExample output
observer analyze example-nextjs.cdx.json
Analyzed example-nextjs.cdx.json
-- Vulnerabilities --
┌────────────────┬─────────┬────────────────┬──────────┬────────┬──────────────────┬────────────────────────────────────────────────┐
│ Name │ Version │ Identifier │ Severity │ EPSS │ Patched Versions │ Title │
├────────────────┼─────────┼────────────────┼──────────┼────────┼──────────────────┼────────────────────────────────────────────────┤
│ next │ 13.5.3 │ CVE-2025-29927 │ CRITICAL │ 92.08% │ >=13.5.7 │ Authorization Bypass in Next.js Middleware │
├────────────────┼─────────┼────────────────┼──────────┼────────┼──────────────────┼────────────────────────────────────────────────┤
│ braces │ 3.0.2 │ CVE-2024-4068 │ HIGH │ 0.22% │ >=3.0.3 │ Fails to limit number of characters │
├────────────────┼─────────┼────────────────┼──────────┼────────┼──────────────────┼────────────────────────────────────────────────┤
│ @babel/runtime │ 7.21.5 │ CVE-2025-27789 │ MEDIUM │ 0.07% │ >=7.24.4 │ Inefficient RegExp complexity │
├────────────────┼─────────┼────────────────┼──────────┼────────┼──────────────────┼────────────────────────────────────────────────┤
│ cookie │ 0.5.0 │ CVE-2024-47764 │ LOW │ 0.07% │ >=0.7.0 │ Accepts name with out of bounds characters │
└────────────────┴─────────┴────────────────┴──────────┴────────┴──────────────────┴────────────────────────────────────────────────┘
-- Policy Violations --
┌──────────┬──────────────────┬────────────────────────────────┬────────────────────────────────────────┬──────────┐
│ Name │ Version │ Policy │ Message │ Severity │
├──────────┼──────────────────┼────────────────────────────────┼────────────────────────────────────────┼──────────┤
│ frontend │ 85448d7aa1f38ad3 │ NTIA Minimum Elements for SBOM │ metadata.supplier is missing │ MEDIUM │
└──────────┴──────────────────┴────────────────────────────────┴────────────────────────────────────────┴──────────┘
-- Summary --
┌───────────────────┬──────────┬──────┬────────┬─────┬───────┐
│ │ CRITICAL │ HIGH │ MEDIUM │ LOW │ Total │
├───────────────────┼──────────┼──────┼────────┼─────┼───────┤
│ Vulnerabilities │ 1 │ 1 │ 1 │ 1 │ 4 │
├───────────────────┼──────────┼──────┼────────┼─────┼───────┤
│ Policy Violations │ 0 │ 0 │ 1 │ 0 │ 1 │
└───────────────────┴──────────┴──────┴────────┴─────┴───────┘With --summary, analyze prints only the summary table.
Next steps
- CI/CD integration to run these steps in a pipeline.
- First policy to define what counts as a violation.
- See the CLI reference for the complete command set.