← Back to projects

Security evidence in your build

Generate your SBOM, submit it for analysis, and keep the findings and printable report with your build artifacts.

1. Get the scanner

Download the Node.js CI script. Review and commit it to your repository. Requires Node.js 22 or later.

2. Scan your inventory

SBOMTRIAGE_URL=https://sbomtriage.dev node ci-scan.mjs sbom.json

Accepts CycloneDX JSON and SPDX JSON. Use a deployment that’s approved for the inventory you upload. The script uses the anonymous API and doesn’t update a saved project.

3. Decide your build policy

Set SBOMTRIAGE_FAIL_ON to fix-now (default), fix-soon, or none. Incomplete assessments always fail the gate.

4. Keep the evidence

Save sbomtriage-results/report.json and report.html as restricted build artifacts. Print the HTML report from your browser to save a PDF.

Anyone with an anonymous report link can open it until it expires, so keep report identifiers private. Rate and capacity limits apply. A passing gate isn’t a security certification.

Try a scan