This chapter explains how to create a software bill of materials (SBOM) manifest for analysis by Red Hat Trusted Profile Analyzer (RHTPA).
Chapter-3- AsciiDoc instructions for generating SBOM manifestsChapter 30- Additional chapter content
Install Syft for your workstation. Red Hat's Syft Technology Preview is also available through the Red Hat Ecosystem Catalog.
RHTPA supports these JSON SBOM formats:
- CycloneDX 1.3, 1.4, 1.5, and 1.6
- SPDX 2.2 and 2.3
Create a CycloneDX SBOM from a container image:
syft registry:example.io/hello-world:latest -o cyclonedx-json@1.5Create an SPDX SBOM from a container image:
syft registry:example.io/hello-world:latest -o spdx-json@2.3Create an SBOM from a local directory or file:
syft dir:. -o cyclonedx-json@1.5
syft file:/example-binary -o spdx-json@2.3See the Syft documentation for supported image and file-system sources.