sbomlyze
Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.
File Explorer
- beta-feedback.yml
- ci.yml
- deploy-site.yml
- marketplace-smoke.yml
- monthly-maintenance.yml
- release-please.yml
- release.yml
- scorecard.yml
- sync-site-version.yml
- update-pkg-repo.yml
- dependabot.yml
- action.js
- baseline.js
- download.js
- github.js
- process.js
- action.test.js
- index.js
- main.go
- main_test.go
- snapshot_test.go
- tamper-drift-demo.gif
- cyclonedx-tool-center-issue.md
- cyclonedx-tool-center.json
- spdx-tool-request.md
- manifest-vs-sbom-vs-integrity-drift.md
- compliance.json
- comprehensive.json
- sample.json
- security.json
- strict.json
- syft-companion.yml
- analysis_test.go
- dependencies.go
- dependencies_test.go
- drift.go
- drift_test.go
- duplicates.go
- duplicates_test.go
- findings.go
- findings_test.go
- stats.go
- stats_test.go
- options.go
- options_test.go
- usage.go
- compliance.go
- compliance_test.go
- convert.go
- convert_test.go
- cyclonedx.go
- cyclonedx_test.go
- realdata_test.go
- roundtrip_test.go
- spdx.go
- spdx_test.go
- syft.go
- syft_test.go
- identity.go
- identity_test.go
- format.go
- format_test.go
- html.go
- html_test.go
- integration_test.go
- junit.go
- markdown.go
- patch.go
- sarif.go
- text.go
- text_test.go
- pager.go
- pager_test.go
- policy.go
- policy_test.go
- spinner.go
- spinner_test.go
- 485c676423d0f043
- deb1475e7f160e82
- bench_test.go
- component.go
- cyclonedx.go
- cyclonedx_test.go
- cyclonedx_xml_test.go
- diff.go
- diff_test.go
- fuzz_test.go
- integration_test.go
- normalize.go
- normalize_test.go
- parser.go
- parser_test.go
- spdx.go
- spdx_test.go
- syft.go
- syft_test.go
- tui.go
- views.go
- version.go
- app.js
- index.html
- style.css
- embed.go
- filesystem.go
- filesystem_test.go
- handlers.go
- handlers_test.go
- server.go
- server_test.go
- build-tamper-drift-demo.sh
- review-snapshots.sh
- main.css
- _index.md
- action.md
- cli.md
- compliance.md
- install.md
- integrity-drift.md
- action.yaml
- cli.yaml
- compliance.yaml
- drift.yaml
- home.yaml
- action.html
- baseof.html
- cli.html
- compliance.html
- drift.html
- install.html
- index.html
- interactive-sbom.gif
- tamper-drift-demo.gif
- web-ui-explorer.png
- CNAME
- hugo.toml
- README.md
- convert_cdx_to_spdx.exitcode
- convert_cdx_to_spdx.stderr
- convert_cdx_to_spdx.stdout
- convert_cdx_to_syft.exitcode
- convert_cdx_to_syft.stderr
- convert_cdx_to_syft.stdout
- convert_invalid_format.exitcode
- convert_invalid_format.stderr
- convert_invalid_format.stdout
- convert_no_input.exitcode
- convert_no_input.stderr
- convert_no_input.stdout
- convert_no_target.exitcode
- convert_no_target.stderr
- convert_no_target.stdout
- convert_spdx_to_cdx.exitcode
- convert_spdx_to_cdx.stderr
- convert_spdx_to_cdx.stdout
- convert_syft_to_cdx.exitcode
- convert_syft_to_cdx.stderr
- convert_syft_to_cdx.stdout
- cross_format_diff.exitcode
- cross_format_diff.stderr
- cross_format_diff.stdout
- diff_integrity_drift_json.exitcode
- diff_integrity_drift_json.stderr
- diff_integrity_drift_json.stdout
- diff_integrity_drift_text.exitcode
- diff_integrity_drift_text.stderr
- diff_integrity_drift_text.stdout
- diff_json.exitcode
- diff_json.stderr
- diff_json.stdout
- diff_no_differences.exitcode
- diff_no_differences.stderr
- diff_no_differences.stdout
- diff_text.exitcode
- diff_text.stderr
- diff_text.stdout
- format_junit.exitcode
- format_junit.stderr
- format_junit.stdout
- format_markdown.exitcode
- format_markdown.stderr
- format_markdown.stdout
- format_patch.exitcode
- format_patch.stderr
- format_patch.stdout
- format_sarif.exitcode
- format_sarif.stderr
- format_sarif.stdout
- help_long.exitcode
- help_long.stderr
- help_long.stdout
- invalid_policy_file.exitcode
- invalid_policy_file.stderr
- invalid_policy_file.stdout
- no_args.exitcode
- no_args.stderr
- no_args.stdout
- nonexistent_file_strict.exitcode
- nonexistent_file_strict.stderr
- nonexistent_file_strict.stdout
- policy_all_rules.exitcode
- policy_all_rules.stderr
- policy_all_rules.stdout
- policy_pass.exitcode
- policy_pass.stderr
- policy_pass.stdout
- policy_violation_json.exitcode
- policy_violation_json.stderr
- policy_violation_json.stdout
- policy_violation_text.exitcode
- policy_violation_text.stderr
- policy_violation_text.stdout
- stats_cyclonedx_json.exitcode
- stats_cyclonedx_json.stderr
- stats_cyclonedx_json.stdout
- stats_cyclonedx_text.exitcode
- stats_cyclonedx_text.stderr
- stats_cyclonedx_text.stdout
- stats_empty_components_text.exitcode
- stats_empty_components_text.stderr
- stats_empty_components_text.stdout
- stats_no_components_text.exitcode
- stats_no_components_text.stderr
- stats_no_components_text.stdout
- stats_spdx_json.exitcode
- stats_spdx_json.stderr
- stats_spdx_json.stdout
- stats_spdx_text.exitcode
- stats_spdx_text.stderr
- stats_spdx_text.stdout
- stats_syft_json.exitcode
- stats_syft_json.stderr
- stats_syft_json.stdout
- stats_syft_text.exitcode
- stats_syft_text.stderr
- stats_syft_text.stdout
- strict_invalid_file.exitcode
- strict_invalid_file.stderr
- strict_invalid_file.stdout
- tolerant_invalid_file.exitcode
- tolerant_invalid_file.stderr
- tolerant_invalid_file.stdout
- version_long.exitcode
- version_long.stderr
- version_long.stdout
- version_short.exitcode
- version_short.stderr
- version_short.stdout
- cyclonedx-after.json
- cyclonedx-before.json
- cyclonedx-before.xml
- cyclonedx-complex-licenses.json
- cyclonedx-empty-components.json
- cyclonedx-integrity-drift.json
- cyclonedx-no-components.json
- cyclonedx-with-metadata.json
- cyclonedx-with-metadata.xml
- empty.json
- invalid.json
- malformed.json
- not-json.txt
- policy-all-rules.json
- policy-warnings-only.json
- real-cyclonedx-alpine.json
- real-cyclonedx-node.json
- real-spdx-alpine.json
- real-syft-alpine.json
- real-syft-python.json
- spdx-complex.json
- spdx-no-packages.json
- spdx-sample.json
- spdx-with-cpes.json
- strict-test-policy.json
- syft-distro-array.json
- syft-malformed-artifact.json
- syft-no-source.json
- syft-sample.json
- syft-with-relationships.json
- test-policy.json
- .gitignore
- .goreleaser.yml
- .release-please-manifest.json
- ACTION.md
- action.yml
- BETA.md
- CHANGELOG.md
- CONTRIBUTING.md
- go.mod
- go.sum
- install.sh
- LICENSE
- Makefile
- README.md
- release-please-config.json
- SECURITY.md
# Use via CDN
jsDelivrjsDelivr serves any public GitHub repository as a CDN with zero setup. Pick a version and a file to get a ready-to-paste link and snippet.
Command Glossary
Commands referenced in this DOCs, explained below.
brew install
View Details ▼
brew install
Install a Homebrew formula or cask.
brew install {{formula|cask}}
Install a formula/cask:
brew install {{[-s|--build-from-source]}} {{formula}}
Build and install a formula from source (dependencies will still be installed from bottles):
brew install {{[-n|--dry-run]}} {{formula|cask}}
Download the manifest, print what would be installed but don't actually install anything:
git clone
View Details ▼
git clone
Clone an existing repository.
git clone {{remote_repository_location}} {{path/to/directory}}
Clone an existing repository into a new directory (the default directory is the repository name):
git clone --recursive {{remote_repository_location}}
Clone an existing repository and its submodules:
git clone {{[-n|--no-checkout]}} {{remote_repository_location}}
Clone only the `.git` directory of an existing repository:
git diff
View Details ▼
git diff
Show changes to tracked files.
git diff
Show unstaged changes:
git diff HEAD
Show all uncommitted changes (including staged ones):
git diff --staged
Show only staged (added, but not yet committed) changes:
go build
View Details ▼
go build
Compile Go sources.
go build {{path/to/main.go}}
Compile a 'package main' file (output will be the filename without extension):
go build -o {{path/to/binary}} {{path/to/source.go}}
Compile, specifying the output filename:
go build -o {{path/to/binary}} {{path/to/package}}
Compile a package:
go install
View Details ▼
go install
Compile and install packages named by the import paths.
go install
Compile and install the current package:
go install {{path/to/package}}
Compile and install a specific local package:
go install {{golang.org/x/tools/gopls}}@{{latest}}
Install the latest version of a program, ignoring `go.mod` in the current directory:
go test
View Details ▼
go test
Test Go packages (files have to end with `_test.go`).
Note: `./...` is a Go package pattern understood by Go tooling. It matches the current package and all packages recursively under the current directory.
go test
Test the package found in the current directory:
go test -v
[v]erbosely test the package in the current directory:
go test -v ./...
Test the packages in the current directory and all subdirectories:
syft
View Details ▼
syft
Generate a Software Bill of Materials (SBOM) from container images and filesystems.
syft {{image:tag}}
Generate an SBOM from a container image:
syft {{path/to/directory}}
Generate an SBOM from a local directory:
syft {{path/to/archive.tar}}
Generate an SBOM from a container archive file:
apk
View Details ▼
apk
Alpine Linux package management tool.
apk upgrade {{[-U|--update-cache]}}
Update repository indexes and upgrade all packages:
apk update
Only update repository indexes:
apk add {{package}}
Install a new package:
apt install
View Details ▼
apt install
Install packages for Debian-based distributions.
sudo apt install {{package}}
Install a package, or update it to the latest version:
sudo apt install {{[-V|--verbose-versions]}} {{package}}
Display verbose package version information during installation or update:
apt
View Details ▼
apt
Package manager for Debian-based distributions.
Intended as a user-friendly alternative to `apt-get` for interactive use.
For equivalent commands in other package managers, see <https://wiki.archlinux.org/title/Pacman/Rosetta>.
sudo apt update
Update the list of available packages and versions (recommended before running other `apt` commands):
apt search {{package}}
Search packages by name or description:
apt list {{package}}
Search packages by name only (supports wildcards like `*`):
dnf install
View Details ▼
dnf install
Install packages on Red Hat-based distributions.
sudo dnf {{[in|install]}} {{package1 package2 ...}}
Install packages by name:
sudo dnf {{[in|install]}} {{path/to/file}}
Install a package from a local file:
sudo dnf {{[in|install]}} {{https://example.com/package.rpm}}
Install a package from the internet:
xattr
View Details ▼
xattr
Utility to work with extended filesystem attributes.
xattr -l {{file}}
List key:value extended attributes for a given file:
xattr -w {{attribute_key}} {{attribute_value}} {{file}}
Write an attribute for a given file:
xattr -d {{com.apple.quarantine}} {{file}}
Delete an attribute from a given file:
replace
View Details ▼
replace
Replace files.
See also: `robocopy`, `move`, `del`.
replace {{path\to\file_or_directory}} {{path\to\destination_directory}}
Replace the destination file with the one from the source directory:
replace {{path\to\file_or_directory}} {{path\to\destination_directory}} /a
Add files to the destination directory instead of replacing existing files:
replace {{path\to\file_or_directory}} {{path\to\destination_directory}} /p
Interactively copy multiple files, with a prompt before replacing or adding a destination file:
