Skip to main content

Mobster

The Mobster project is a Python-based tool and ecosystem to work with SBOM (Software Bill of Materials) documents. Its goal is to provide unified interface for generating, manipulating and consuming SBOM documents in various formats.

The tools is designed to cover a whole lifecycle of SBOM documents. The major stages are:

  • Generation: Generate SBOMs document from various sources (Syft, Hermeto, etc.)
  • Augmentation: Augment SBOM documents with additional information that are not present in the phase of generation. This phase is usually done in the release phase where we know more information about the software.
  • Validation: Validate a quality of the SBOM document in different stages of the lifecycle. The validation is done by the Product Security team guidelines.
  • Distribution: Distribute the SBOM document to various set of locations (e.g. Trusted Profile Analyzer, container registry, etc.)

Getting started

To use the Mobster tool, you need to install it first. There are multiple ways to install the tool:

Using pip

pip install mobster
mobster --help

Using container image

podman pull quay.io/konflux-ci/mobster:latest
podman run -it quay.io/konflux-ci/mobster:latest mobster --help

Additional dependencies

Some features of Mobster require additional dependencies to be installed outside of Python ecosystem. To use those features, you need to install the following tools:

  • oras: Used for pushing and pulling SBOM documents to/from OCI registries.
  • cosign: Used for signing and verifying SBOM documents in OCI registries.
  • syft: Used for generating SBOM documents from container images and filesystems.

Usage

# Generate an SBOM for an OCI image (merging Syft and Hermeto outputs)
mobster generate --output sbom.json oci-image \
  --from-syft syft-sbom.json \
  --image-pullspec registry.example.com/repo:tag \
  --image-digest sha256:<digest>

# Augment SBOMs for all images in a snapshot
mobster augment --output sboms/ oci-image --snapshot snapshot.json

# Upload a single SBOM to Trusted Profile Analyzer
mobster upload tpa \
  --tpa-base-url https://your-tpa-instance.com \
  --file sbom.json

# See all available commands and options
mobster --help
mobster generate --help

Context within Konflux

Mobster is a tool used for creating both Build-time and Release-time SBOMs.

  • Build-time SBOM creation is invoked in konflux-ci/build-definitions repository.
  • Release-time SBOM creation is invoked through tekton tasks (in the tasks/ dir) that are distributed to and used in konflux-ci/release-service-catalog repository.
  • Build-time SBOMs can be contextualized. For builder-content contextualization, Mobster requires metadata output from konflux-ci/capo.

Contributing

See CONTRIBUTING.md for environment setup, running checks, and submitting a pull request.

Resources

Metadata

Release files for mobster 2.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mobster 2.2.0
File Size Uploaded
mobster-2.2.0.tar.gz 118.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mobster 2.2.0
File Interpreter ABI Platform
mobster-2.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 272.6 kB

Release files / mobster-2.2.0.tar.gz

Download URL mobster-2.2.0.tar.gz
Size 118.4 kB
Tags Source
SHA-256 checksum
How to use checksums
e88ad5a5500f1b0b01a392cf7bcbc7a6fa1235b319c6b2821e67389d160c83a5
BLAKE2b-256 checksum
How to use checksums
a22181c3bf9078b8efb2ec8ee2ac80c58621e9cf14c1c8d57a5764a4275dc234
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 17, 2026.

Transparency log

Release files / mobster-2.2.0-py3-none-any.whl

Download URL mobster-2.2.0-py3-none-any.whl
Size 154.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
84d236f57f349ac0ea56d0bc7a78d4874b9d267eed1b3f7271be7f8bd1a3e996
BLAKE2b-256 checksum
How to use checksums
47787683e095c48d223eba6a5b317d9d6dd41681fa16a213ea3c5402a3c0a36f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 17, 2026.

Transparency log

Release history Release notifications | RSS feed

2.3.0

2 release files

This release

2.2.0 This release

2 release files

2.1.0

2 release files

2.0.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page