Generate and upload SBOMs
Generate an SBOM with Observer CLI or another tool, and upload it in the web interface, with the CLI, or through the API.
Generate an SBOM with Observer CLI or any tool that writes CycloneDX or SPDX, then upload it in the web interface, with the CLI, or through the API.
To upload from a terminal or a pipeline, install Observer CLI and create an access token.
Generate an SBOM
Observer CLI writes CycloneDX SBOMs.
From source code, detecting the ecosystems it supports:
observer fs -o sbom.cdx.json .From a container image:
observer image -o sbom.cdx.json myapp:latestFrom a Kubernetes cluster, requiring kubectl access:
observer k8s --sbom --uploadSee the CLI reference for more commands and options.
Any tool that writes CycloneDX or SPDX works, for example Trivy, Syft, CycloneDX cdxgen, or SPDX Tools.
With Syft:
syft . -o cyclonedx-json > sbom.cdx.jsonWith Trivy:
trivy fs --format cyclonedx . > sbom.cdx.jsonFormats and standards lists the CycloneDX and SPDX versions and encodings SBOM Observer accepts.
Upload an SBOM
Sign in to SBOM Observer, open Attestations, select Upload, and add the CycloneDX or SPDX file.
Create an access token first. The namespace is the name in the app URL after /workspace/; the CLI uses default when none is set.
export OBSERVER_TOKEN='{your-api-token}'
export OBSERVER_NAMESPACE='{namespace}' # optional, default "default"
observer upload sbom.cdx.jsonIn CI/CD, store OBSERVER_TOKEN as a pipeline secret, never in the repository.
Use an access token as a bearer token and post the file as the multipart field files:
export OBSERVER_ENDPOINT=https://cloud.sbom.observer # or your self-hosted URL
export OBSERVER_TOKEN='{your-api-token}'
export OBSERVER_NAMESPACE='{namespace}'
curl -X POST \
-H "Authorization: Bearer $OBSERVER_TOKEN" \
-F "files=@sbom.cdx.json" \
"$OBSERVER_ENDPOINT/api/v1/$OBSERVER_NAMESPACE/attestations"In CI/CD, store OBSERVER_TOKEN as a pipeline secret, never in the repository.
An upload can be compressed: a gzip file is unpacked, and every file in a zip archive is imported. Observer CLI 0.17.0 and later compresses files before uploading them. One upload can be at most 16 MB.
What happens after upload
SBOM Observer adds the SBOM's components to the namespace index, matches them against vulnerability data, and evaluates all policies. The SBOM shows on the Attestations page, its components under Components, and any new violations under Policy Violations. Components are rescanned later, so vulnerabilities disclosed after the upload still appear.
Next steps
- First policy to flag the components you care about.
- Enforce policies in CI/CD to fail a build when an SBOM breaks a policy.
- Analyze vulnerability impact to see which applications and projects a vulnerability reaches.
- CI/CD integration to generate and upload an SBOM on every build.
Evaluate open source components
Check the open source project behind a component on the OSS Insights tab, with repository activity, the OpenSSF Scorecard, and SLSA provenance.
Generate SBOMs at build time
Trace a build with eBPF to create an SBOM that includes the OS packages and toolchain the build used.