Skip to main content

CWL 2 SBOM

PyPI - Version PyPI - Python Version GitHub Actions Workflow Status Code coverage

Generate local CycloneDX SBOMs for the containers declared by a CWL workflow using Trivy. Bootstrapped from the Transpiler-Mate plugin project template.

Install

Python 3.10+ and an installed Trivy executable are required. From this checkout:

pip install transpiler-mate-runtime .

Generate

transpiler-mate cwl2sbom --platform linux/amd64 --output sbom \
  workflow.cwl#main

For the workspace example:

transpiler-mate cwl2sbom --platform linux/amd64 \
  --output tmp/build/burned-area-severity/sbom \
  tmp/burned-area-severity.cwl#burned-area-severity

An explicit CWL entrypoint and platform are required. Trivy downloads and inspects images directly from their registries; no Docker daemon or container execution is involved. Registry authentication uses Trivy's normal configuration. Install Trivy separately; the plugin does not download executables.

Output Contents
workflow.cdx.json CycloneDX 1.5 workflow → tool invocation → container inventory
images/*.cdx.json Original Trivy SBOM for each distinct image reference and platform
images.lock.json Original references, reported repository digests and image IDs, platform, step associations, checksums, and generator versions
coverage.json Covered declarations, uncovered tools, and expression tools

Image filenames hash the original reference and platform, avoiding registry aliases and unsafe filename characters. Repeated references are inspected once per invocation. Different aliases may be inspected separately, even if they ultimately resolve to the same image. Trivy's cache handles reuse of downloaded/analyzed content.

Options

Option Default Purpose
--platform required OCI platform, such as linux/amd64 or linux/arm64/v8
--output sbom New directory; existing directories are rejected
--trivy trivy Installed executable name or path
--cache-dir Trivy default Persistent Trivy cache directory
--timeout 600 Seconds per Trivy invocation
--allow-incomplete false Export known containers and report uncovered tools

The plugin follows nested workflows and effective Docker requirements/hints. It reports missing containers, nonliteral references, and build-only Docker requirements. ExpressionTools are marked not applicable because they run in the CWL engine. No image builds are performed. Failure removes the newly created bundle; existing outputs are preserved.

Publish and scan separately

Publish or attach the generated files using your existing ORAS pipeline. This plugin does not push, retrieve OCI referrers, sign artifacts, or attach SBOMs. The lock file connects each image SBOM to its container identity even when the bundle is attached to a workflow artifact.

See the offline Trivy scanning guide for database preparation and transfer, per-image vulnerability reports, separate license assessment, and CI exit-code handling. Scanning and policy enforcement run downstream of this plugin.

Scope and reproducibility

A tag is resolved by Trivy during inspection. The lock records the repository digest(s) and image configuration ID reported by that inspection, together with the requested platform. It does not pre-resolve tags or rewrite CWL. A reported repository digest can identify a multi-platform index: it must not be mistaken for a selected child manifest digest. For subsequent reproducible invocations, use digest-pinned references and the same platform. The lock file is an audit output, not an input replay mechanism.

A successful bundle covers declared container references; it is not a complete inventory of software that might execute. Runtime downloads, host tools, CWL engine dependencies, and packages Trivy cannot detect are outside its scope. Docker hints describe possible execution environments, not proof of an actual run. The workflow inventory therefore explicitly declares its composition incomplete. Image SBOMs are retained without merging away package or distribution metadata needed by Trivy.

Development

pip install -e '.[test]'
pytest
hatch run dev:typecheck
hatch run dev:ruff check src tests
hatch run dev:ruff format --check src tests
hatch run dev:security
pip install -r requirements-docs.txt
mkdocs build --strict

Verified with Trivy 0.74.0 against alpine:3.21 on linux/amd64.

Tests use controlled scanner responses and require no registry access. Real Trivy scanning is a separate integration check. See architecture.

License

Apache License, Version 2.0

Metadata

Release files for cwl2sbom 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cwl2sbom 0.1.1
File Size Uploaded
cwl2sbom-0.1.1.tar.gz 22.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cwl2sbom 0.1.1
File Interpreter ABI Platform
cwl2sbom-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 37.9 kB

Release files / cwl2sbom-0.1.1.tar.gz

Download URL cwl2sbom-0.1.1.tar.gz
Size 22.2 kB
Tags Source
SHA-256 checksum
How to use checksums
b800027c544421ee566ab48f17f55c46d7d92a834916fdf00259500cfdc4bb1c
BLAKE2b-256 checksum
How to use checksums
4cfea4d23f0aa48b212f15bb221584f921b5a88665a11681a9bd1ac6c078fd5c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / cwl2sbom-0.1.1-py3-none-any.whl

Download URL cwl2sbom-0.1.1-py3-none-any.whl
Size 15.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4e085897d75563dc7f436b4f596f5bfcc3da6a0edebddbb9ae39fd9f25ce1426
BLAKE2b-256 checksum
How to use checksums
227c9825703a086bf45b5bffdc14643e1c4a78b0e2f01dadefce84dea224a059
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page