Skip to content

Guardrails / supply-chain

The build produced a software bill of materials ​

supply-chain/sbom-present@v1

An SBOM was produced for this build, so the components that went into the artifact are recorded at build time instead of reconstructed later.

Idsupply-chain/sbom-present
Versionv1
Categorysupply-chain
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectssbom

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
sbomThe components a build says it ships, read from the bill of materials it already wrote (CycloneDX or SPDX, in JSON, XML or tag-value) and normalized into one list with the licence each component names.none

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "supply-chain/sbom-present@v1",
              "severity": "error",
              "with": {
                  "minComponents": "1"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
minComponentsFewest components an SBOM must list to count. A document that lists none is not an inventory.1GUARDRAIL_INPUT_MINCOMPONENTS

How to fix ​

Generate an SBOM in the pipeline and leave it in the workspace before buildnote guardrails runs:

bash
syft dir:. -o cyclonedx-json=bom.json

Gradle and Maven have plugins that generate one from the resolved dependency graph, which is more accurate than scanning the file tree. A missing SBOM is the violation. An SBOM answers "which releases contain package X at version Y", a question you get asked the day the next Log4Shell lands, when reconstructing the answer is far too slow.

More in supply-chain ​

All 6 supply-chain guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412