ChatSBOM
Talk to your Supply Chain. Chat with SBOMs.
ChatSBOM is a CLI tool for indexing and querying Software Bill of Materials (SBOM) data, providing deep insights into project dependencies.
Features
- Discover: Find high-quality repositories on GitHub by stars and language.
- Collect: Enrich metadata and fetch dependency files (
go.mod,package.json, etc.). - Generate: Transform files into standard SBOM format using Syft.
- Index: Load SBOM data into ClickHouse for high-performance queries.
- Query: Use the CLI for stats/searches to get insights into project dependencies.
- Chat: Use the AI-powered natural language chat to chat with SBOM data.
Getting Started
1. Prerequisites
2. Installation
# Via pip
pip install chatsbom
# Via pipx
pipx install chatsbom
# Or run directly via uvx
uvx chatsbom
3. Setup
Start Database
Option 1: Using docker compose
docker compose up -d
Option 2: Using docker run
docker run -d --name clickhouse -p 8123:8123 --ulimit nofile=262144:262144 clickhouse/clickhouse-server:25.12-alpine
docker exec clickhouse clickhouse-client -q "CREATE DATABASE IF NOT EXISTS chatsbom"
docker exec clickhouse clickhouse-client -q "CREATE USER IF NOT EXISTS admin IDENTIFIED BY 'admin'"
docker exec clickhouse clickhouse-client -q "GRANT ALL ON *.* TO admin WITH GRANT OPTION"
docker exec clickhouse clickhouse-client -q "CREATE USER IF NOT EXISTS guest IDENTIFIED BY 'guest'"
docker exec clickhouse clickhouse-client -q "GRANT SELECT ON chatsbom.* TO guest"
docker exec clickhouse clickhouse-client -q "ALTER USER guest SET PROFILE readonly"
Configure Environment: Set your API keys
export GITHUB_TOKEN="your_github_token"
export ANTHROPIC_AUTH_TOKEN="your_anthropic_token"
4. Basic Workflow
# 1. Search and collect data
chatsbom github search --language go --min-stars 10000
chatsbom github repo --language go
chatsbom github release --language go
chatsbom github commit --language go
chatsbom github content --language go
# 2. Generate and index SBOMs
chatsbom sbom generate --language go
chatsbom db index --language go
# 3. Query insights
chatsbom db status
chatsbom db query gin
chatsbom chat
Use Case: Analyzing Framework Adoption
Find the most popular projects depending on a specific library (e.g., gin) using natural language.
Release files for chatsbom 0.5.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| chatsbom-0.5.4.tar.gz | 39.1 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| chatsbom-0.5.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 39.1 MB
Release files / chatsbom-0.5.4.tar.gz
| Download URL | chatsbom-0.5.4.tar.gz |
|---|---|
| Size | 39.1 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8dd0b2844cb7eac1ab62c0cbf8862768fbbf2f1802963df9bd3f43d0a73fa90b
|
|
BLAKE2b-256 checksum How to use checksums |
17cacb7dc16ea8b68b6c5602b7dc8cca853783d0eb8bbe5d62747127e6b13958
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / chatsbom-0.5.4-py3-none-any.whl
| Download URL | chatsbom-0.5.4-py3-none-any.whl |
|---|---|
| Size | 52.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2304770a52081ab5b02758801874e3a604e15689f2e4422c91acd9e8d8650086
|
|
BLAKE2b-256 checksum How to use checksums |
e565a8c9b3d6f089d4403c53f48a0f71a47776e8b5d8ec6b7335ef253b07d932
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|