返回更新列表
新发布Aug 4, 2026

sbomlyze v0.3.6

SBOM 的 Git diff——比较 CycloneDX、SPDX 和 Syft 文档,检测篡改,并对 CI 进行门禁。

分享

sbomlyze

适用于您的 SBOM 的 git diff。 比较两份软件物料清单 (SBOM),查看构建、版本和发布之间发生了什么变化。

sbomlyze 比较组件哈希,而不仅仅是版本字符串。当攻击者在未升级版本的情况下替换软件包时,sbomlyze 会将其标记出来。生成器和漏洞扫描器会错过这一点。

[![CI][ci-img]][ci] [![GitHub Marketplace][marketplace-img]][marketplace] [![GitHub Release][release-img]][release] [![Go Report Card][go-report-img]][go-report] [![OpenSSF Scorecard][scorecard-img]][scorecard] [![License: Apache-2.0][license-img]][license] [![Downloads][download-img]][download]

SBOMlyze 在真实拉取请求中阻止了同版本哈希变更

在清单差异 vs. SBOM 差异 vs. 完整性漂移中了解为什么该信号与清单或普通组件差异不同。

生成器生成 SBOM,扫描器发现 CVE。sbomlyze 告诉你两份 SBOM 之间发生了什么变化,以及是否值得信任。 在生成器之后运行它:syft image:tag -o cyclonedx-json | sbomlyze - --compliance 可在不创建临时文件的情况下分析并评分生成的 SBOM。将其与基线进行比较,以对漂移进行分类并为你流水线设置门控。

GitHub Action 快速入门

添加 [来自 GitHub Marketplace 的 SBOMlyze Diff][marketplace],以将已检入或单独生成的 SBOM 与其 git 基线进行比较。下面的不可变 SHA 是已发布的 v0.5.1 Action:```yaml steps:

  • uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0

  • uses: rezmoss/sbomlyze@31503690611fda8ebba4ed2bd186eda000442594 # v0.5.1 with: sbom-path: build/sbom.cdx.json

默认情况下,Action 会写入 Job Summary,并可强制执行策略、报告
完整性漂移、上传 SARIF,或维护单条拉取请求评论。请参阅
[完整 Action 参考](https://github.com/rezmoss/sbomlyze/blob/main/ACTION.md) 了解输入、输出、权限,
以及安全指南。请参阅
[在线演示仓库](https://github.com/rezmoss/sbomlyze-action-demo)
查看通过依赖更新和受阻的同版本哈希变更,其中包含
公开工作流运行记录和 SARIF 证据。

如需按特定格式进行自测,请使用公共
[Go + SPDX](https://github.com/rezmoss/sbomlyze-go-spdx-demo),
[Node + CycloneDX](https://github.com/rezmoss/sbomlyze-node-cyclonedx-demo),或
[container](https://github.com/rezmoss/sbomlyze-container-demo) 示例。每个
示例都包含五个可复现的审查场景。
[10 分钟 Beta 指南](https://github.com/rezmoss/sbomlyze/blob/main/BETA.md) 汇总了四个重点的激活与信号
质量问题。

生成的 SBOM 无需提交:`baseline: workflow-artifact`
会从一次成功的默认分支
运行中检索最新的匹配工件。一个 [固定的 Syft 伴生工作流](https://github.com/rezmoss/sbomlyze/blob/main/examples/workflows/syft-companion.yml)
展示了生成和基线发布,而 SBOMlyze 仍负责
审查和策略。

## 为什么选择 sbomlyze?

许多工具都能生成 SBOM。只有少数工具会进行比较,更少的工具能告诉你某个变更是常规更新还是供应链危险信号。sbomlyze 填补了这一空白。

| 能力 | **sbomlyze** | cyclonedx-cli | sbomqs | syft / trivy |
|---|:---:|:---:|:---:|:---:|
| SBOM 到 SBOM **差异** | ✅ | 基础 | ❌ | ❌ |
| **完整性 / 篡改**漂移(哈希变化但版本未变) | ✅ | ❌ | ❌ | ❌ |
| 依赖图差异 + 传递深度风险 | ✅ | ❌ | ❌ | ❌ |
| **NTIA / CISA / BSI** 合规评分 | ✅ | ❌ | ✅ | ❌ |
| 格式转换(Syft / CycloneDX / SPDX) | ✅ | ✅ | ❌ | 部分 |
| **TUI + Web UI** 探索器 | ✅ | ❌ | ❌ | ❌ |
| 策略门禁 + SARIF / JUnit / Markdown / HTML / Patch | ✅ | 部分 | 部分 | 部分 |

## 功能特性

- **SBOM 差异比较**:比较两个 SBOM,一目了然地查看新增、移除和变更的组件
- **漂移分类**:区分版本漂移与**完整性漂移**(哈希值在版本未变时发生变化,可能表明被篡改)以及元数据漂移
- **合规评分**:根据 **NTIA**、**CISA 2025** 和 **BSI TR-03183** 最低要素对任意 SBOM 进行评分
- **依赖图差异**:追踪传递依赖和供应链深度
- **多格式支持**:Syft、CycloneDX、SPDX(JSON)
- **格式转换**:在 CycloneDX、SPDX 和 Syft 格式之间转换
- **强身份匹配**:PURL → CPE → BOM-ref → 命名空间/名称优先级
- **统计模式**:分析单个 SBOM 的许可证、依赖和完整性指标
- **交互式 TUI 模式**:通过键盘导航和搜索浏览 SBOM
- **Web UI 模式**:基于浏览器的 SBOM 探索器,支持拖放上传
- **策略引擎**:在 CI 流水线中强制执行漂移、许可证和合规评分规则
- **GitHub Marketplace Action**:通过 Job Summary、SARIF 和可选评论输出,在 SBOM 漂移上对拉取请求进行门控
- **重复与冲突检测**:发现同一包的多个版本以及模糊的身份匹配
- **多种输出格式**:Text、JSON、SARIF、JUnit XML、Markdown、HTML、JSON Patch
- **容错解析**:出错时继续运行,并给出结构化警告

## 安装

### Homebrew (macOS/Linux)```bash
brew install rezmoss/sbomlyze/sbomlyze

安装脚本

安装脚本会根据你的操作系统/架构下载对应的二进制文件:```bash

Install to ./bin

curl -sSfL https://raw.githubusercontent.com/rezmoss/sbomlyze/main/install.sh | sh

Install to /usr/local/bin (requires sudo)

curl -sSfL https://raw.githubusercontent.com/rezmoss/sbomlyze/main/install.sh | sudo sh -s -- -b /usr/local/bin

Install specific version

curl -sSfL https://raw.githubusercontent.com/rezmoss/sbomlyze/main/install.sh | sh -s -- -v 0.4.0

**安装程序选项:**

| 选项 | 描述 |
|------|------|
| `-b <dir>` | 安装目录(默认:`./bin`) |
| `-d` | 启用调试输出 |
| `-v <ver>` | 安装特定版本(默认:最新) |

安装程序始终验证发行版的校验和。当安装了兼容的 GitHub CLI 时,它还会验证发行版的构建来源,如果验证未成功,则会安全终止。

### Go 安装```bash
go install github.com/rezmoss/sbomlyze/cmd/sbomlyze@latest

从二进制发行版

从 GitHub Releases 下载最新的二进制文件。

从 v0.3.7 开始,发布归档会随附 GitHub 工件证明(artifact attestations)。如需独立验证下载,请使用:```bash gh attestation verify ./sbomlyze_0.4.0_Linux_x86_64.tar.gz
--repo rezmoss/sbomlyze
--signer-workflow rezmoss/sbomlyze/.github/workflows/release.yml

未签名的 apt、rpm 和 apk 仓库说明已被移除,直到
这些仓库支持包管理器原生的签名验证为止。

**macOS 用户:** 下载后请移除隔离标志:```bash
xattr -d com.apple.quarantine ./sbomlyze
chmod +x ./sbomlyze

从源码构建```bash

git clone https://github.com/rezmoss/sbomlyze.git cd sbomlyze go build -o sbomlyze ./cmd/sbomlyze

## 快速开始```bash
# Compare two SBOMs (the headline use case)
sbomlyze before.json after.json

# Analyze a single SBOM
sbomlyze image.json

# Read an SBOM from standard input
syft image:tag -o cyclonedx-json | sbomlyze -

# Use standard input on either side of a diff
syft image:tag -o cyclonedx-json | sbomlyze baseline.json -

# Score an SBOM against NTIA / CISA / BSI minimum elements
sbomlyze image.json --compliance

# Interactive TUI explorer
sbomlyze image.json -i

# Web UI (opens browser)
sbomlyze -web

# Convert between SBOM formats
sbomlyze convert syft.json --to spdx
sbomlyze convert cdx.json --to syft -o output.json

# JSON output for CI integration
sbomlyze before.json after.json --json

# SARIF output for GitHub Code Scanning
sbomlyze before.json after.json --format sarif

# Markdown report for PR comments
sbomlyze before.json after.json --format markdown

# Apply policy checks
sbomlyze before.json after.json --policy policy.json

用法```

sbomlyze <sbom1|-> [sbom2|-] [options] sbomlyze convert <sbom|-> --to [-o output]

Modes: Single file: sbomlyze [--json] Show statistics Interactive: sbomlyze -i Interactive explorer Convert: sbomlyze convert --to Convert SBOM format Web server: sbomlyze -web [--port 8080] Web UI explorer Two files: sbomlyze [...] Show diff

Use - in place of one SBOM path to read it from standard input.

Options: -i, --interactive Interactive TUI explorer -web, --web Start web UI server --port Web server port (default 8080) --json Output in JSON format (shortcut for --format json) --format Output format: text, json, sarif, junit, markdown, html, patch --compliance Show NTIA/CISA/BSI compliance scoring --policy Policy file for CI checks --strict Fail on parse warnings --tolerant Continue on parse warnings (default) --no-pager Disable automatic paging of output --to Target format for convert: cyclonedx (cdx), spdx, syft -o, --output Output file for convert (default: stdout) --version, -v Show version information --help, -h Show this help message

## 命令

### 统计模式(单个文件)

分析 SBOM 以获取有关组件、许可证和依赖项的见解。```bash
sbomlyze image.json

输出包括扫描上下文、自动检测的关键发现和统计信息:``` Scan Context: Tool: syft 1.40.1 Schema: 16.0.18 Scan Scope: all-layers Source Type: image Source: alpine:latest

Key Findings: 💻 OS/Distro: Alpine Linux v3.21 📦 Dominated by apk: 71 of 71 packages (100.0%) 📂 8,542 files tracked on filesystem 🔗 Relationships: 71 containment + 64 dependency 📜 License profile: 72% permissive, 20% copyleft ⚠️ Low hash coverage: 0.0% (71 of 71 missing) 🔍 Top catalogers: apkdb-cataloger (71)

📦 SBOM Statistics

Total Components: 71

By Package Type: apk 71

Licenses: With license: 71 Without license: 0

分类