CI/CD SBOM ingestion
Generate an SBOM at build time (syft, cdxgen, trivy, cyclonedx-npm …) and push it. Vellaci creates or reuses the product version, deduplicates by content hash, parses, matches vulnerabilities and evaluates the release gate.
GitHub Actions
- name: Generate SBOM
run: syft . -o cyclonedx-json > sbom.cdx.json
- name: Upload to Vellaci
run: |
curl -sS -f -X POST "$VELLACI_URL/api/v1/sboms/upload" \
-H "Authorization: Bearer $VELLACI_TOKEN" \
-F file=@sbom.cdx.json -F product=sensorlink-firmware \
-F version=${GITHUB_REF_NAME} -F commit_sha=${GITHUB_SHA} -F tool=syft
env:
VELLACI_URL: https://www.vellaci.ch
VELLACI_TOKEN: ${{ secrets.VELLACI_TOKEN }}GitLab CI
sbom:
stage: test
script:
- syft . -o cyclonedx-json > sbom.cdx.json
- curl -sS -f -X POST "$VELLACI_URL/api/v1/sboms/upload" -H "Authorization: Bearer $VELLACI_TOKEN" -F file=@sbom.cdx.json -F product=$CI_PROJECT_NAME -F version=$CI_COMMIT_TAG -F commit_sha=$CI_COMMIT_SHA
rules:
- if: $CI_COMMIT_TAGJenkins (declarative)
stage('SBOM') { steps { sh 'syft . -o cyclonedx-json > sbom.cdx.json'
withCredentials([string(credentialsId: 'vellaci-token', variable: 'VELLACI_TOKEN')]) {
sh 'curl -sS -f -X POST "$VELLACI_URL/api/v1/sboms/upload" -H "Authorization: Bearer $VELLACI_TOKEN" -F file=@sbom.cdx.json -F product=edgegate-router -F version=$TAG_NAME'
} } }CircleCI
- run: syft . -o cyclonedx-json > sbom.cdx.json - run: curl -sS -f -X POST "$VELLACI_URL/api/v1/sboms/upload" -H "Authorization: Bearer $VELLACI_TOKEN" -F file=@sbom.cdx.json -F product=edgegate-router -F version=$CIRCLE_TAG
Vellaci CLI
npx vellaci auth --url https://www.vellaci.ch npx vellaci sbom upload sbom.cdx.json --product edgegate-router --version 3.2.1 --wait
Poll GET /api/v1/sboms/{id} (or --wait) for validation_status, vulnerability_match_status and the vulnerability summary; fail the build on your own thresholds.
Last updated . This page describes the current release.