nvidia/openshell

sbom

Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.

First seen Mar 18, 2026

Installation

$ npx skills add nvidia/openshell --skill sbom

Summary

  • Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.
  • Covers SBOM generation with Syft, license resolution via public registries, and CSV export for compliance review.
  • Trigger keywords - SBOM, sbom, bill of materials, license audit, license resolution, generate sbom, sbom csv, dependency license, supply chain, license scan.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from nvidia/openshell · top by installs.

npx skills add nvidia/openshell

Browse all from nvidia/openshell

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 8.5K
License LICENSE
Default branch main
Open issues 399
Status Active

Skill metadata

Parsed from SKILL.md frontmatter.

More metadata
internal
1

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 5,252 B
  • docs SUMMARY.md 365 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 16 installs

SKILL.md

SBOM Generation and License Resolution

Generate CycloneDX SBOMs, resolve missing licenses, and export to CSV for compliance review.

Overview

The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft, resolves missing or hash-based licenses by querying public registries (crates.io, npm, PyPI), and exports the results to CSV for stakeholder review.

SBOMs are release artifacts only -- they are generated on demand and not committed to the repository. Output lands in deploy/sbom/output/ (gitignored).

Pushed gateway and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.

Prerequisites

  • mise install has been run (installs Syft and other tools)
  • The repository is checked out at the root

Inspecting an Image SBOM

BuildKit uses its default Syft scanner and attaches one SPDX document per platform. Read one without pulling the image:

docker buildx imagetools inspect ghcr.io/nvidia/openshell/gateway:latest \
  --format '{{ json (index .SBOM "linux/amd64").SPDX }}'

Validate the final attestation, requiring a Cargo package for an auditable image:

tasks/scripts/verify-image-sbom.sh ghcr.io/nvidia/openshell/gateway:latest --require-cargo

Inspecting an Auditable Image Binary

Opt into auditable metadata when staging a local image binary:

OPENSHELL_AUDITABLE=1 PREBUILT_ARCH=amd64 \
  tasks/scripts/stage-prebuilt-binaries.sh gateway

Scan the staged binary rather than the source tree:

mise x -- syft \
  "file:deploy/docker/.build/prebuilt-binaries/amd64/openshell-gateway" \
  -o cyclonedx-json

This output is limited to packages Syft discovers from that binary. Use mise run sbom for the broader source-tree license-compliance inventory.

Workflow 1: Full SBOM Generation (One Command)

mise run sbom

This single command chains three stages:

  1. Generate (sbom:generate): Syft scans the workspace source tree and produces a CycloneDX JSON SBOM
  2. Resolve (sbom:resolve): Public registry APIs fill in missing or hash-based licenses in the JSON
  3. CSV (sbom:csv): JSON SBOMs are converted to CSV for review

Output directory: deploy/sbom/output/

After running, the user can find:

  • deploy/sbom/output/*.cdx.json -- full CycloneDX SBOMs
  • deploy/sbom/output/*.csv -- CSV exports ready for spreadsheet review

Workflow 2: Individual Stages

Run stages independently when debugging or iterating:

mise run sbom:generate   # Generate JSON SBOMs only (requires Syft)
mise run sbom:resolve    # Resolve licenses in existing JSONs (queries APIs)
mise run sbom:csv        # Convert existing JSONs to CSV

Workflow 3: License Check (CI Advisory)

mise run sbom:check

Reports unresolved licenses without failing. Intended for PR CI as a non-blocking advisory check. Requires that SBOMs have already been generated (mise run sbom:generate).

Workflow 4: Processing External SBOMs

The Python scripts accept explicit file paths, so they can process SBOMs from any source (e.g., NVIDIA nSpect pipeline output):

uv run python deploy/sbom/resolve_licenses.py /path/to/external-sbom.json
uv run python deploy/sbom/sbom_to_csv.py /path/to/external-sbom.json

License Resolution Details

The resolver queries these public registries:

Registry Package URL prefix Method
crates.io pkg:cargo/* REST API
npm pkg:npm/* Registry API
PyPI pkg:pypi/* JSON API
Go modules pkg:golang/* Known license map (no API)
Debian/Ubuntu pkg:deb/* Known license map

Components from private registries (e.g., @openclaw/* npm packages) are not resolved and will appear in the "unresolved" report.

Output Files

Pattern Description
deploy/sbom/output/openshell-source-{version}.cdx.json CycloneDX JSON SBOM
deploy/sbom/output/openshell-source-{version}.csv CSV export (name, version, type, purl, licenses, bom-ref)

Key Files

File Purpose
deploy/sbom/resolve_licenses.py License resolution script
deploy/sbom/sbomtocsv.py JSON-to-CSV converter
tasks/sbom.toml Mise task definitions
mise.toml Syft tool definition (under [tools])

Quick Reference

Task Command
Full pipeline mise run sbom
Generate only mise run sbom:generate
Resolve licenses mise run sbom:resolve
Export CSV mise run sbom:csv
CI license check mise run sbom:check
Process external SBOM uv run python deploy/sbom/resolve_licenses.py <file>