build-flow-labs/Blueprint

SBOM generation and vulnerability analysis for software supply chain security

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
commandCommand to run: sbom or vulnyes
formatSBOM format (cyclonedx-json, cyclonedx-xml, spdx-json)nocyclonedx-json
pathPath to scan for dependency files (for sbom command)no.
trivy-resultsPath to Trivy JSON results file (for vuln command)no
thresholdVulnerability gate threshold (no_critical, no_critical_high, no_critical_high_medium, no_vulnerabilities)nono_critical_high
ignore-unfixedIgnore vulnerabilities without available fixesnofalse
outputOutput file path for SBOMno
namedescription
sbomGenerated SBOM content (JSON)
sbom-filePath to generated SBOM file
passes-gateWhether vulnerability gate passed (true/false)
vulnerability-summaryVulnerability summary as JSON