Skip to main content

SBOM for RPM

SBOM4RPM uses existing rpm and dnf features to resolve all dependencies of one or multiple RPM packages and generates an SBOM for each .rpm.

Usage

Start a container for building the custom RPM project and mount its directory into it. For example:

podman run -it -v <path-to-project>:/var/<your-project> <build-container> /bin/bash

Proceed by building the custom RPM project and create a repomd (xml-based rpm metadata) repository for your output directory:

# assuming all rpms have been put into '/tmp/custom-artifacts'
createrepo_c /tmp/custom-artifacts

Then install and run SBOM4RPMs:

pip install sbom4rpms
sbom4rpms --rpm-dir=/tmp/custom-artifacts/ --collect-dependencies --sbom-format=spdx --sbom-dir=sboms

Example: BlueChi

The example directory provides collected data and generated SBOMs for BlueChi.

Metadata

Release files for sbom4rpms 0.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sbom4rpms 0.0.2
File Size Uploaded
sbom4rpms-0.0.2.tar.gz 10.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sbom4rpms 0.0.2
File Interpreter ABI Platform
sbom4rpms-0.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 25.8 kB

Release files / sbom4rpms-0.0.2.tar.gz

Download URL sbom4rpms-0.0.2.tar.gz
Size 10.9 kB
Tags Source
SHA-256 checksum
How to use checksums
03414e58ec67b29ac518bbbb15457d0456b00fa0dc4b21ef462fa5aa10140af8
BLAKE2b-256 checksum
How to use checksums
ba8e3d9171bc7a272b0547d5a617b9c33579b40118d02399400727741aedc924
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.12.3

Release files / sbom4rpms-0.0.2-py3-none-any.whl

Download URL sbom4rpms-0.0.2-py3-none-any.whl
Size 14.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b576edc56150412c8da6482095773dfd80f0443397431ad8c1b1fdc9a39ccde2
BLAKE2b-256 checksum
How to use checksums
f96fbfe5da0b543b479e4b47a99f3ac59ff3024e97d08dabb990dd09be87b932
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.0.2 This release

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page