SBOM for RPM
SBOM4RPM uses existing rpm and dnf features to resolve all dependencies of one or multiple RPM packages and generates an SBOM for each .rpm.
Usage
Start a container for building the custom RPM project and mount its directory into it. For example:
podman run -it -v <path-to-project>:/var/<your-project> <build-container> /bin/bash
Proceed by building the custom RPM project and create a repomd (xml-based rpm metadata) repository for your output directory:
# assuming all rpms have been put into '/tmp/custom-artifacts'
createrepo_c /tmp/custom-artifacts
Then install and run SBOM4RPMs:
pip install sbom4rpms
sbom4rpms --rpm-dir=/tmp/custom-artifacts/ --collect-dependencies --sbom-format=spdx --sbom-dir=sboms
Example: BlueChi
The example directory provides collected data and generated SBOMs for BlueChi.
Metadata
Release files for sbom4rpms 0.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sbom4rpms-0.0.2.tar.gz | 10.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sbom4rpms-0.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.8 kB
Release files / sbom4rpms-0.0.2.tar.gz
| Download URL | sbom4rpms-0.0.2.tar.gz |
|---|---|
| Size | 10.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
03414e58ec67b29ac518bbbb15457d0456b00fa0dc4b21ef462fa5aa10140af8
|
|
BLAKE2b-256 checksum How to use checksums |
ba8e3d9171bc7a272b0547d5a617b9c33579b40118d02399400727741aedc924
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/5.0.0 CPython/3.12.3
|
Release files / sbom4rpms-0.0.2-py3-none-any.whl
| Download URL | sbom4rpms-0.0.2-py3-none-any.whl |
|---|---|
| Size | 14.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b576edc56150412c8da6482095773dfd80f0443397431ad8c1b1fdc9a39ccde2
|
|
BLAKE2b-256 checksum How to use checksums |
f96fbfe5da0b543b479e4b47a99f3ac59ff3024e97d08dabb990dd09be87b932
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/5.0.0 CPython/3.12.3
|