An SBOM lists the software components and versions included in a project. For more about the term, see the glossary.
Prerequisites
- You must be signed in to XEIZE.
- You must be able to view the target project.
- The SCA feature must be enabled.
- For projects registered through Git, the connected Git service must allow access to the source.
- For Manual Upload projects, the uploaded source must still be available.
Generating and downloading an SBOM does not require the Admin role. You do not need to run an SCA scan first. If SCA is unavailable, the SBOM option appears locked.
Supported formats
| Selection | Generated format | File extension |
|---|---|---|
SPDX |
SPDX 2.3 Tag/Value text | .spdx |
CycloneDX |
CycloneDX 1.6 JSON | .cdx.json |
Each generation request uses the same format for all selected projects. If you need both formats, generate each separately.
Generate an SBOM for one project
- Open
Projects > Overview. - Open the more menu on the right of the project row.
- Select
Export > SBOM. - Select
SPDXorCycloneDXinGenerate SBOM. - Generation starts as soon as you select a format, without a separate confirmation step.
- When the status becomes
Ready, select the download icon in that row.
Generate SBOMs for multiple projects
You can select multiple projects.
- Select the target projects' checkboxes in
Projects > Overview. - You can select projects across pages. The checkbox in the table header selects only projects on the current page.
- Select
SBOM (N)above the table. - Select the output format in
Generate SBOM. - Wait until processing finishes for every project.
- Use the row download icon for each
Readyproject. When all processing finishes, you can also selectDownload Allto download all ready files.
Download All does not create a ZIP archive. It downloads each project's SBOM as a separate file in sequence. If the browser blocks multiple downloads, allow the site to download multiple files.
Generation status
| Status | Meaning |
|---|---|
Queued |
The request has been received and is waiting its turn. |
Generating |
The SBOM is being generated. |
Ready |
Generation is complete and the file can be downloaded. |
No Data |
No component information is available to download. |
Failed |
Generation failed. |
Download All excludes projects with a No Data or Failed status.
Downloaded files
SPDX filenames use the project name followed by .spdx. CycloneDX filenames use the project name followed by .cdx.json.
Troubleshooting
The SBOM option is locked
The SCA feature is unavailable. Ask your administrator to check the product license and whether SCA is enabled.
Generation fails
For projects registered through Git, check access to the connected Git service and repository. For Manual Upload projects, check that the uploaded source is available. If the problem continues, ask your administrator to check the source connection and SBOM generation service.
The status stays queued or generating
After a short wait, close the dialog, reopen it, and select the same format. If the status still does not change, ask your administrator to check the SBOM generation service.
Download All does not start
Check that your browser allows multiple file downloads. Download All downloads only files with a Ready status.
Download fails
Check that you are signed in and have access to the project, then retry. If the same error recurs, contact your administrator.