Company
Date Published
Author
Eric Tooley, Courtney Claessens
Word count
307
Language
English
Hacker News points
None

Summary

GitHub has introduced a new Export SBOM function, enabling users with read access to cloud repositories to generate Software Bills of Materials (SBOMs) in compliance with the National Telecommunications and Information Administration (NTIA) with just one click. This feature produces a JSON file in the SPDX format, detailing project dependencies and metadata, which can be integrated into security and compliance workflows or converted for use in spreadsheet applications like Microsoft Excel. The tool is part of GitHub's supply chain security offerings and is free for all cloud repositories, allowing developers to make SBOM generation a standard part of their development process. Users can upload existing SBOMs to receive vulnerability alerts through GitHub's Dependabot, use the SBOM gh CLI extension for automated generation, or employ third-party GitHub Actions during build times. Additionally, a REST API for SBOM generation is in development, further enhancing GitHub's capabilities in managing supply chain security.