Generate an SBOM
Supported formats
List them anytime:
Supported manifests
sbom generate reads these dependency manifests:
By default, development dependencies are excluded. Include them with
--include-dev.
Options
See
mergeguide sbom.
Scan dependencies for vulnerabilities
An SBOM inventories your dependencies; to check them against known vulnerabilities, run the vulnerability scanner:Next steps
OSCAL export
Export NIST OSCAL compliance evidence.
Compliance overview
How evidence fits your audit.