Security evidence in your build
Generate your SBOM, submit it for analysis, and keep the findings and printable report with your build artifacts.
1. Get the scanner
Download the Node.js CI script. Review and commit it to your repository. Requires Node.js 22 or later.
2. Scan your inventory
SBOMTRIAGE_URL=https://sbomtriage.dev node ci-scan.mjs sbom.json
Accepts CycloneDX JSON and SPDX JSON. Use a deployment that’s approved for the inventory you upload. The script uses the anonymous API and doesn’t update a saved project.
3. Decide your build policy
Set SBOMTRIAGE_FAIL_ON to fix-now (default), fix-soon, or none. Incomplete assessments always fail the gate.
- Exit 0: Configured gate passed.
- Exit 1: Risk threshold exceeded.
- Exit 2: The assessment was incomplete, or the scan failed.
4. Keep the evidence
Save sbomtriage-results/report.json and report.html as restricted build artifacts. Print the HTML report from your browser to save a PDF.