Skip to content
kix /docs
Install the CLI

How-to guide Policy, CI, and compliance

Generate a CycloneDX SBOM

Create a CycloneDX inventory of a cluster's packages, container images, and flake inputs.

Use kix compliance sbom to produce a CycloneDX 1.6 software bill of materials from a rendered cluster. The command evaluates the cluster locally and does not need Kubernetes access.

Pass the cluster name and redirect stdout to a file:

kix-examples/
❱ kix compliance sbom 19-scorecards > sbom.json

The output is JSON by default. This captured excerpt shows the document type, cluster component, component counts, and dependency count:

kix-examples/ output excerpt offline capture
❱ kix compliance sbom 19-scorecards
Show outputHide output · 44 lines
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "metadata": {
    "component": {
      "bom-ref": "cluster-19-scorecards",
      "description": "kix cluster 19-scorecards",
      "name": "cluster-19-scorecards",
      "properties": [
        {
          "name": "kix:activation-hash",
          "value": "03lwg2rc2h1m1x5y1fx5nnq8m0saj5pi"
        },
        {
          "name": "kix:flake-ref",
          "value": "kix-examples"
        }
      ],
      "type": "platform",
      "version": "activation-03lwg2rc2h1m1x5y1fx5nnq8m0saj5pi"
    }
  },
  "componentTypes": [
    {
      "type": "application",
      "count": 6
    },
    {
      "type": "container",
      "count": 2
    },
    {
      "type": "library",
      "count": 3
    }
  ],
  "dependencyCount": 7
}
Building cluster '19-scorecards'...
  Evaluating cluster '19-scorecards'...
  Reading package index...
  Loading store graph...
  Reading 6 packages...
  Computing cross-package dependencies...

The complete file contains:

  • One platform component for the cluster.
  • One application component for each package instance.
  • One deduplicated container component for each image reference.
  • One library component for each locked flake input.
  • Dependency edges between the cluster, packages, images, and inputs.

An image component includes a SHA-256 hash when its rendered reference has an @sha256: digest.

Check that the command produced a CycloneDX 1.6 document:

kix-examples/
❱ jq -e '.bomFormat == "CycloneDX" and .specVersion == "1.6"' sbom.json

The capture pipeline runs this same assertion on every regeneration, so a change to the emitted CycloneDX version fails the docs build rather than reaching you as a surprise.

Use --output yaml if the receiving system expects YAML:

kix-examples/
❱ kix --output yaml compliance sbom 19-scorecards > sbom.yaml