Skip to main content

Welcome to sbomtools

WARNING

This package is early in development. May cause warts or indigestion. Save your work. Interfaces subject to change without notice.

This package contains a handful of routines to search and update SBOMs. JSON versions of both CycloneDX and SPDX are supported.

Building

  1. Bop the version on setup.cfg
  2. python3 -m build -w
  3. cd dist
  4. pip3 install that file

Usage

sbomls

usage: sbomls [-h] [-j] [-1] -f FILENAME [components ...]

Where-

  • -j produces JSON entries that match. The JSON will be of the appropriate form for a component for CycloneDX or a package for SPDX.
  • -1 produces a single entry per line. Otherwise, a tabbed list is produced a'la ls(1).
  • -f is the filename of the SBOM to use. Format is automatically detected.
  • one or more components may optionally be named. Wildcards are permitted.

Returns a list of matching components (or all).

sbomgrep

% sbomgrep [-j] search-string [file [file...]]

Results are similar to grep. If no file is specified, stdin will be used.

To search from python

from sbomtools import sbom_grep

from sbom tools import sbom_grep
results= sbom_grep(filename, searchstr,file_pointer, want_json = True)

Where

  • filename is nothing more than a strong for search results. This is done simply to emulate grep behavior fro pretty printing.
  • searchstr is a regex, sbom is a JSON format of an SBOM, and
  • file_pointer is the successful result of open() or sys.stdin
  • want_json is whether you want the entire entry for each result.

The function will automatically detect the input format.

results is either a printable string of results or (sbom_type,jsonstring) where SBOM type is either sbomtools.FORMAT_CDX or sbomtools.FORMAT_SPDX.

sbomupdate

This routine updates an SBOM file by adding a single entry. Again, it will do this for both SPDX and CycloneDx. For CycloneDX both the components and refs are updated. For SPDX, products, relationships, and documentDescribes are updated. N.B., SPDX takes as input dependencies by short name. You don't need to enter the SPDXID.

usage: sbomupdate.py [-h] -f FILENAME -n NAME -v VERSION [-s SUPPLIER] [-e EMAIL] [-u URL]
                 [--sha256 SHA256] [--sha1 SHA1] [--md5 MD5] [-w WEBSITE]
                 [-O | --overwrite | --no-overwrite]
                 [-d DEPENDENCIES [DEPENDENCIES ...]]

Cross-dependencies are not currently supported. However, one can add both entries and then update each referencing one another.

To call from python:

from sbomtools import sbom_update
sbom_update(filename,component_name,version, supplier, email
		url, sha256, sha1, md5, website, overwrite=False, deps)

Where

  • filename is the name of the SBOM file to update (stdin is not acceptable)
  • component_name is the name of the component to add/update
  • supplier is the descriptive name of the supplier
  • email is the email of the supplier
  • sha256, sha1, md5 are respective hashes
  • website is the homepage of the package
  • overwrite is a flag to indicate whether to overwrite an existing entry
  • deps is an array of dependencies to be added for this package.

sbomrm

This routine removes one or more SBOM entries. Once again, it is format neutral. Note, it tries to disentangle SPDX dependencies, and will do so only for DEPENDENCY_OF and DEPENDS_ON. The other relationships are TBD.

usage: sbomrm [-h] -f FILENAME [-r | --recurse | --no-recurse]
               NAME [NAME ...]

This one works with cross-dependencies, if you use -r. Heh.

To call from python:

from sbomtools import sbom_rm

sbom_rm(filename, component_name, recurse)

Where

  • filename is the name of the SBOM file to act on
  • component_name is the name of the component to remove
  • recurse says to remove those packages that are dependent on this component

The following exceptions are defined:

  • PackageNotFound: you tried to edit/remove a package that wasn't present.
  • DependencyNotMet: you tried to remove something that had a dependency and you didn't use -r.
  • AlreadyExists: you tried to add an entry that already exists, and you didn't use -O
  • FileFormatError: there is something wrong with the JSON or the SBOM.
  • UnknownError: Something weird happened. Open an Issue ;-(

Metadata

Release files for sbomtools 0.3.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sbomtools 0.3.3
File Size Uploaded
sbomtools-0.3.3.tar.gz 11.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sbomtools 0.3.3
File Interpreter ABI Platform
sbomtools-0.3.3-py3-none-any.whl Python 3 none any Details

Total release size: 26.9 kB

Release files / sbomtools-0.3.3.tar.gz

Download URL sbomtools-0.3.3.tar.gz
Size 11.8 kB
Tags Source
SHA-256 checksum
How to use checksums
04340169e5578cbd8765d1e41cf4ad0053e4f700157cd242171de3a078f7366a
BLAKE2b-256 checksum
How to use checksums
7eb9f13f671dd3e4a18539e7e5d297e47cabab6cc5fcf3b1029e672981232281
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.7.1 importlib_metadata/4.10.1 pkginfo/1.8.2 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.15

Release files / sbomtools-0.3.3-py3-none-any.whl

Download URL sbomtools-0.3.3-py3-none-any.whl
Size 15.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
234f23c1a8373303bab740e3cab1ebdfe9abfb89f06f8d19a4e9bddb7fff1b51
BLAKE2b-256 checksum
How to use checksums
847c6b9099d7a9d22999e0992011e1ff0d8e9a0401951d424b8b138eb2c2bc5e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.7.1 importlib_metadata/4.10.1 pkginfo/1.8.2 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.15

Release history Release notifications | RSS feed

This release

0.3.3 This release

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page