{"repo":"louib/nix2sbom","free":true,"listed":false,"github":"https://github.com/louib/nix2sbom","clone":"git clone https://github.com/louib/nix2sbom.git","description":"nix2sbom extracts the CycloneDX and SPDX SBOM (Software Bill of Materials) from a Nix derivation","language":"Rust","stars":18,"topics":["cyclonedx","nix","nixos","sbom","sbom-generator","purl","software-bill-of-materials","security","github-actions","supply-chain"],"license":"MIT","category":"security-tools","readme_excerpt":"nix2sbom nix2sbom extracts the SBOM (Software Bill of Materials) from a Nix derivation 📚 Documentation is here Features Supports CycloneDX 1.4 format Supports SPDX 2.3 format (Experimental) Supports JSON and YAML serialization formats Generates a SBOM for your current NixOS system Detects and handles patches Discovers git URLs (using archive URLs) Using In GitHub Actions Here is an example of how to generate an SPDX manifest for your nix flake in a GHA workflow: Installing With Nix Assuming that you have enabled both the flakes and nix-command experimental features: With Cargo","default_branch":null,"files":null,"tree":[],"storefront":"/r/louib","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/louib/nix2sbom/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}