CI/CD SBOM ingestion

Generate an SBOM at build time (syft, cdxgen, trivy, cyclonedx-npm …) and push it. Vellaci creates or reuses the product version, deduplicates by content hash, parses, matches vulnerabilities and evaluates the release gate.

GitHub Actions

- name: Generate SBOM
  run: syft . -o cyclonedx-json > sbom.cdx.json
- name: Upload to Vellaci
  run: |
    curl -sS -f -X POST "$VELLACI_URL/api/v1/sboms/upload" \
      -H "Authorization: Bearer $VELLACI_TOKEN" \
      -F file=@sbom.cdx.json -F product=sensorlink-firmware \
      -F version=${GITHUB_REF_NAME} -F commit_sha=${GITHUB_SHA} -F tool=syft
  env:
    VELLACI_URL: https://www.vellaci.ch
    VELLACI_TOKEN: ${{ secrets.VELLACI_TOKEN }}

GitLab CI

sbom:
  stage: test
  script:
    - syft . -o cyclonedx-json > sbom.cdx.json
    - curl -sS -f -X POST "$VELLACI_URL/api/v1/sboms/upload" -H "Authorization: Bearer $VELLACI_TOKEN" -F file=@sbom.cdx.json -F product=$CI_PROJECT_NAME -F version=$CI_COMMIT_TAG -F commit_sha=$CI_COMMIT_SHA
  rules:
    - if: $CI_COMMIT_TAG

Jenkins (declarative)

stage('SBOM') { steps { sh 'syft . -o cyclonedx-json > sbom.cdx.json'
  withCredentials([string(credentialsId: 'vellaci-token', variable: 'VELLACI_TOKEN')]) {
    sh 'curl -sS -f -X POST "$VELLACI_URL/api/v1/sboms/upload" -H "Authorization: Bearer $VELLACI_TOKEN" -F file=@sbom.cdx.json -F product=edgegate-router -F version=$TAG_NAME'
  } } }

CircleCI

- run: syft . -o cyclonedx-json > sbom.cdx.json
- run: curl -sS -f -X POST "$VELLACI_URL/api/v1/sboms/upload" -H "Authorization: Bearer $VELLACI_TOKEN" -F file=@sbom.cdx.json -F product=edgegate-router -F version=$CIRCLE_TAG

Vellaci CLI

npx vellaci auth --url https://www.vellaci.ch
npx vellaci sbom upload sbom.cdx.json --product edgegate-router --version 3.2.1 --wait

Poll GET /api/v1/sboms/{id} (or --wait) for validation_status, vulnerability_match_status and the vulnerability summary; fail the build on your own thresholds.

Last updated . This page describes the current release.