SBOMs
Zarf builds Software Bill of Materials (SBOM) into packages to help with the management of software being brought into the airgap.
By default, Zarf will generate SBOMs for all components in a package and include them in the package itself. This means that wherever you end up moving your package, you will always be able to take a peek inside to see what it contains. If you would like to skip this behavior you can use the --skip-sbom flag when creating a package.
Extracting a Package’s SBOM
# copy the SBOMs of a package to a directoryzarf package inspect sbom <package source> --output <output directory>ls <output directory>/<package name>This extracts the package’s SBOM files into a subdirectory named after the package. Zarf generates SBOMs in Syft .json format, which can be used with tools such as Grype for vulnerability checking.
The Syft .json files can also be converted to other formats with the Syft CLI (which is vendored into Zarf) including spdx-json and cyclonedx-json.
zarf tools sbom convert nginx_1.23.0.json -o cyclonedx-json > nginx_1.23.0.cyclonedx.jsonTo learn more about the formats Syft supports see zarf tools sbom convert.
How SBOMs are Generated
Zarf uses Syft under the hood to provide SBOMs for container images, as well as files and dataInjections included in components. This is run during the final step of package creation with the SBOM information for a package being placed within an sboms directory at the root of the Zarf Package tarball. Additionally, the SBOMs are created in the Syft .json format which is a superset of all of the information that Syft can discover and is used so that we can provide the most information possible even when performing lossy conversions to formats like spdx-json or cyclonedx-json.
If you were using the Syft CLI to create these SBOM files manually this would be equivalent to the following commands:
# For `images` contained within the package$ syft packages oci-dir:path/to/yourimage -o json > my-sbom.json# For `files` or `dataInjections` contained within the package$ syft packages file:path/to/yourproject/file -o json > my-sbom.json