Skip to main content

SBOM export

Code audit assessments can export a Software Bill of Materials as CycloneDX 1.5 or SPDX 2.3 JSON. Use this when a vendor questionnaire, customer security review, procurement process, or supply-chain tool asks for a machine-readable component inventory.

AISafe builds the SBOM from the same dependency inventory shown in the Dependency Risk panel. You download the file from the assessment detail page when SBOM export is enabled for your organization. AISafe reads the inventory within a fixed limit, and it refuses the download if that read cannot finish. As a result, a file you do download is never only the first page of a large repository's inventory, cut off without warning.

What the export contains​

  • package name, ecosystem, and version when the code graph can resolve one;
  • package URL coordinates where the ecosystem is known;
  • dependency scope, such as production or development;
  • license, homepage, and description when the manifest or lockfile provides them.

Formats​

FormatUse it for
CycloneDX 1.5Dependency-Track, OWASP/NTIA-style SBOM workflows, and modern supply-chain security tooling.
SPDX 2.3Procurement, legal, licensing, and ecosystem workflows that standardize on SPDX.

Coverage caveats​

The SBOM reflects source dependency metadata AISafe extracts from manifests and lockfiles. It is not a runtime attestation, and you should not treat it as a complete inventory of every component loaded in production.

  • Lockfiles provide the strongest version confidence.
  • Manifest ranges may not identify the exact installed version.
  • Transitive coverage depends on the ecosystem and whether a lockfile is available.
  • The pricing scan runs offline. It does not call OSV or a package registry, and the SBOM does not claim that an unlisted advisory is absent.