Last reviewed: 2026-09-08
Software bill of materials
Generate an SBOM from a lockfile project unit for dependency inventory, export, and review without consuming scan credits.
Dependency inventory from a lockfile
An SBOM lists the resolved dependencies in a project unit’s lockfile. Use it to inventory software components, hand evidence to procurement or customers, and compare the dependency set across commits.
Generate only an SBOM
You can generate an SBOM without starting a vulnerability scan and without using credits (default path). Optionally enable Refresh evidence in the wizard to billably re-scan missing/stale units at the branch tip before merge — the SBOM merge step itself stays free.
Review the output
Verify the project unit, branch, and commit before exporting. A project with multiple lockfiles can produce different inventories; generate the SBOM for the unit that represents the deliverable you are assessing. Regenerate it after dependency updates so exported evidence matches the shipped lockfile.
When an Auditor Export Pack includes SBOM files, it copies the latest on-file SBOM per project unit (soft-skip if missing) and marks SHA-stale entries in Coverage — it does not regenerate SBOM at pack time.
Limits
An SBOM describes the resolved dependency inventory; it is not a vulnerability decision, license approval, or proof of provenance. Pair it with dependency security and license policy when those decisions are required.
When platform signing keys are configured, exported CycloneDX documents include a JWS (RS512) signature over the BOM payload (the signature field). Absolute worker paths are stripped before persist and export. Verify with the platform public key (for example node scripts/verify-sbom.mjs <sbom.json> [public-key.pem] on the API host).