Generate and upload SBOMs

Generate an SBOM with Observer CLI or another tool, and upload it in the web interface, with the CLI, or through the API.

Generate an SBOM with Observer CLI or any tool that writes CycloneDX or SPDX, then upload it in the web interface, with the CLI, or through the API.

To upload from a terminal or a pipeline, install Observer CLI and create an access token.

Generate an SBOM

Observer CLI writes CycloneDX SBOMs.

From source code, detecting the ecosystems it supports:

observer fs -o sbom.cdx.json .

From a container image:

observer image -o sbom.cdx.json myapp:latest

From a Kubernetes cluster, requiring kubectl access:

observer k8s --sbom --upload

See the CLI reference for more commands and options.

Any tool that writes CycloneDX or SPDX works, for example Trivy, Syft, CycloneDX cdxgen, or SPDX Tools.

With Syft:

syft . -o cyclonedx-json > sbom.cdx.json

With Trivy:

trivy fs --format cyclonedx . > sbom.cdx.json

Formats and standards lists the CycloneDX and SPDX versions and encodings SBOM Observer accepts.

Upload an SBOM

Sign in to SBOM Observer, open Attestations, select Upload, and add the CycloneDX or SPDX file.

Create an access token first. The namespace is the name in the app URL after /workspace/; the CLI uses default when none is set.

export OBSERVER_TOKEN='{your-api-token}'
export OBSERVER_NAMESPACE='{namespace}' # optional, default "default"

observer upload sbom.cdx.json

In CI/CD, store OBSERVER_TOKEN as a pipeline secret, never in the repository.

Use an access token as a bearer token and post the file as the multipart field files:

export OBSERVER_ENDPOINT=https://cloud.sbom.observer   # or your self-hosted URL
export OBSERVER_TOKEN='{your-api-token}'
export OBSERVER_NAMESPACE='{namespace}'

curl -X POST \
  -H "Authorization: Bearer $OBSERVER_TOKEN" \
  -F "files=@sbom.cdx.json" \
  "$OBSERVER_ENDPOINT/api/v1/$OBSERVER_NAMESPACE/attestations"

In CI/CD, store OBSERVER_TOKEN as a pipeline secret, never in the repository.

An upload can be compressed: a gzip file is unpacked, and every file in a zip archive is imported. Observer CLI 0.17.0 and later compresses files before uploading them. One upload can be at most 16 MB.

What happens after upload

SBOM Observer adds the SBOM's components to the namespace index, matches them against vulnerability data, and evaluates all policies. The SBOM shows on the Attestations page, its components under Components, and any new violations under Policy Violations. Components are rescanned later, so vulnerabilities disclosed after the upload still appear.

Next steps