Mobster
The Mobster project is a Python-based tool and ecosystem to work with SBOM (Software Bill of Materials) documents. Its goal is to provide unified interface for generating, manipulating and consuming SBOM documents in various formats.
The tools is designed to cover a whole lifecycle of SBOM documents. The major stages are:
- Generation: Generate SBOMs document from various sources (Syft, Hermeto, etc.)
- Augmentation: Augment SBOM documents with additional information that are not present in the phase of generation. This phase is usually done in the release phase where we know more information about the software.
- Validation: Validate a quality of the SBOM document in different stages of the lifecycle. The validation is done by the Product Security team guidelines.
- Distribution: Distribute the SBOM document to various set of locations (e.g. Trusted Profile Analyzer, container registry, etc.)
Getting started
To use the Mobster tool, you need to install it first. There are multiple ways to install the tool:
Using pip
pip install mobster
mobster --help
Using container image
podman pull quay.io/konflux-ci/mobster:latest
podman run -it quay.io/konflux-ci/mobster:latest mobster --help
Additional dependencies
Some features of Mobster require additional dependencies to be installed outside of Python ecosystem. To use those features, you need to install the following tools:
- oras: Used for pushing and pulling SBOM documents to/from OCI registries.
- cosign: Used for signing and verifying SBOM documents in OCI registries.
- syft: Used for generating SBOM documents from container images and filesystems.
Usage
# Generate an SBOM for an OCI image (merging Syft and Hermeto outputs)
mobster generate --output sbom.json oci-image \
--from-syft syft-sbom.json \
--image-pullspec registry.example.com/repo:tag \
--image-digest sha256:<digest>
# Augment SBOMs for all images in a snapshot
mobster augment --output sboms/ oci-image --snapshot snapshot.json
# Upload a single SBOM to Trusted Profile Analyzer
mobster upload tpa \
--tpa-base-url https://your-tpa-instance.com \
--file sbom.json
# See all available commands and options
mobster --help
mobster generate --help
Context within Konflux
Mobster is a tool used for creating both Build-time and Release-time SBOMs.
- Build-time SBOM creation is invoked in
konflux-ci/build-definitionsrepository. - Release-time SBOM creation is invoked through tekton tasks (in the
tasks/dir) that are distributed to and used inkonflux-ci/release-service-catalogrepository. - Build-time SBOMs can be contextualized. For builder-content
contextualization, Mobster requires metadata output from
konflux-ci/capo.
Contributing
See CONTRIBUTING.md for environment setup, running checks, and submitting a pull request.
Resources
- Development environment
- Release process
- Full documentation
- License — Apache License 2.0
Metadata
Release files for mobster 2.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mobster-2.3.0.tar.gz | 118.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mobster-2.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 273.1 kB
Release files / mobster-2.3.0.tar.gz
| Download URL | mobster-2.3.0.tar.gz |
|---|---|
| Size | 118.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
875ad64ae0846ba7db5ab9e7af712004b74c28e3d15b2d98bed0b007879321cf
|
|
BLAKE2b-256 checksum How to use checksums |
2514774db78acfae45ea71f7f5b9be967511db32ed2b2721e94d8d6652c5b5ff
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.
Transparency logRelease files / mobster-2.3.0-py3-none-any.whl
| Download URL | mobster-2.3.0-py3-none-any.whl |
|---|---|
| Size | 154.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d23ab57892c3727788db48f77f69d89bcb77d8b972c4f22759920a8e8ba08832
|
|
BLAKE2b-256 checksum How to use checksums |
aa65994fd66ece98093830a7e090727bddc086433b61a1735c13a64d2d0726d3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.
Transparency log