Generate and download an SBOM

Generate project SBOMs in Projects and download them in SPDX or CycloneDX format.

An SBOM lists the software components and versions included in a project. For more about the term, see the glossary.

Prerequisites

  • You must be signed in to XEIZE.
  • You must be able to view the target project.
  • The SCA feature must be enabled.
  • For projects registered through Git, the connected Git service must allow access to the source.
  • For Manual Upload projects, the uploaded source must still be available.

Generating and downloading an SBOM does not require the Admin role. You do not need to run an SCA scan first. If SCA is unavailable, the SBOM option appears locked.

Supported formats

Selection Generated format File extension
SPDX SPDX 2.3 Tag/Value text .spdx
CycloneDX CycloneDX 1.6 JSON .cdx.json

Each generation request uses the same format for all selected projects. If you need both formats, generate each separately.

Generate an SBOM for one project

  1. Open Projects > Overview.
  2. Open the more menu on the right of the project row.
  3. Select Export > SBOM.
  4. Select SPDX or CycloneDX in Generate SBOM.
  5. Generation starts as soon as you select a format, without a separate confirmation step.
  6. When the status becomes Ready, select the download icon in that row.

Generate SBOMs for multiple projects

You can select multiple projects.

  1. Select the target projects' checkboxes in Projects > Overview.
  2. You can select projects across pages. The checkbox in the table header selects only projects on the current page.
  3. Select SBOM (N) above the table.
  4. Select the output format in Generate SBOM.
  5. Wait until processing finishes for every project.
  6. Use the row download icon for each Ready project. When all processing finishes, you can also select Download All to download all ready files.

Download All does not create a ZIP archive. It downloads each project's SBOM as a separate file in sequence. If the browser blocks multiple downloads, allow the site to download multiple files.

Generation status

Status Meaning
Queued The request has been received and is waiting its turn.
Generating The SBOM is being generated.
Ready Generation is complete and the file can be downloaded.
No Data No component information is available to download.
Failed Generation failed.

Download All excludes projects with a No Data or Failed status.

Downloaded files

SPDX filenames use the project name followed by .spdx. CycloneDX filenames use the project name followed by .cdx.json.

Troubleshooting

The SBOM option is locked

The SCA feature is unavailable. Ask your administrator to check the product license and whether SCA is enabled.

Generation fails

For projects registered through Git, check access to the connected Git service and repository. For Manual Upload projects, check that the uploaded source is available. If the problem continues, ask your administrator to check the source connection and SBOM generation service.

The status stays queued or generating

After a short wait, close the dialog, reopen it, and select the same format. If the status still does not change, ask your administrator to check the SBOM generation service.

Download All does not start

Check that your browser allows multiple file downloads. Download All downloads only files with a Ready status.

Download fails

Check that you are signed in and have access to the project, then retry. If the same error recurs, contact your administrator.