Skip to main content
vet supports CycloneDX v1.6 SBOM generation. The generated SBOM lists all packages and their dependencies, including security metadata: detected vulnerabilities, malware, and license information.

Quick Start

Generate an SBOM with a custom application name:
The --report-cdx-app-name parameter is optional. If omitted, Vet will use a default application name.

What’s Included in the SBOM

The generated CycloneDX SBOM contains:

Package Inventory

Complete list of all direct and transitive dependencies

Vulnerability Data

Known vulnerabilities from OSV database and other sources

License Information

License identifiers and compliance data for each component

Malware Detection

Results from malware analysis and threat detection

Advanced Usage

Custom Application Metadata

Provide detailed metadata about your application:

Combined with Other Reports

Generate multiple report formats simultaneously:

Integration with CI/CD

Sample SBOMs

Chat Server SBOM

Example SBOM for a Node.js chat application

Express.js SBOM

Example SBOM for an Express.js web application

SBOM Analysis and Consumption

Viewing SBOM Content

Install the CycloneDX CLI (a .NET global tool) to validate and convert your SBOM:

Integration with Security Tools

Many security tools can consume CycloneDX SBOMs:
  • Dependency Track: Import SBOMs for vulnerability monitoring
  • FOSSA: License compliance analysis
  • Snyk: Security scanning and monitoring
  • JFrog Xray: Artifact analysis and security scanning

Naming Convention

Use a consistent pattern for SBOM filenames:

Troubleshooting

For projects with many dependencies, SBOMs can become large. Consider:
  • Filtering out development dependencies in production SBOMs
  • Using compressed storage formats
  • Implementing SBOM splitting for microservices
If components are missing from your SBOM:
  • Ensure all package manifest files are included in the scan
  • Check that Vet supports your package manager
  • Verify dependencies are properly declared in manifest files
If SBOM validation fails:
  • Check the CycloneDX schema version compatibility
  • Verify all required fields are present
  • Use cyclonedx-cli for detailed validation errors

CycloneDX Documentation

Learn more about the CycloneDX v1.6 JSON specification

Vet Repository

Explore Vet’s complete SBOM generation capabilities

Dependency Inventory

Learn how to create accurate dependency inventories