The CBOM Repository service acts as an object storage wrapper built on top of an S3-compatible backend. It provides a convenient REST API for uploading, retrieving, and searching Cryptographic Bills of Materials (CBOM) documents.
Use the provided Helm chart to deploy the service into your Kubernetes cluster. Please refer to the Helm chart README for detailed installation instructions and configuration options.
This project is currently under active development.
A summary of the available endpoints and methods are below. For the complete specification please see OpenAPI Spec.
Please note that HTTP API Paths have an additional default prefix /api. You can change it by setting the environment variable APP_HTTP_PREFIX.
| Path | HTTP Method | Required Params | Optional Params | Description |
|---|---|---|---|---|
/v1/bom | POST | Contents of BOM in request body and Content-Type header set | Uploads the supplied BOM to the repository | |
/v1/bom | GET | query parameter after | Retrieves a list of BOM serial numbers and versions that were created later that after timestamp | |
/v1/bom/{urn} | GET | query parameter version | If optional query parameter version is not supplied, retrieves the latest version of the BOM from repository | |
/v1/bom/{urn}/versions | GET | List all available versions of a BOM identified by its URN |
Let's see each endpoint in greater detail.
The upload operation requires a valid Content-Type header. At this time, only JSON format using CycloneDX Schema version 1.6 is supported.
This means the Content-Type header must be set to:
application/vnd.cyclonedx+json
Optionally, you may specify an explicit version, for example:
application/vnd.cyclonedx+json; Version=1.6
If a version is provided, the handler will validate the uploaded BOM document against the corresponding CycloneDX schema specification. If no version is supplied, the handler will attempt to decode the BOM and automatically determine the correct schema version to validate against.
Support for additional formats, including the upcoming CycloneDX 1.7 specification, is planned to be added shortly.
When processing uploaded BOMs, the system recognizes several use cases:
Upon successful upload, the endpoint returns basic cryptographic statistics about the provided BOM.
This feature is still a work in progress, and both the format and the details reported may evolve over time.
The search operation requires a single query parameter: after, whose value must be a Unix timestamp.
The endpoint responds with a list of URNs along with all versions created after the specified timestamp.
This allows clients to efficiently discover updates without scanning the entire BOM collection.
The get operation retrieves the latest version of a BOM—i.e., the entry with the highest version number—based on the {urn} supplied in the URL path.
The value of {urn} must conform to RFC 4122, meaning it follows the format:
urn:<NID>:<NSS>
Where:
<NID> — Namespace Identifier, which must be exactly uuid for RFC 4122.<NSS> — Namespace-Specific String, which must be a valid UUID.To retrieve a specific version instead of the latest, you may provide the optional query parameter:
?version=<number>
The following environment variables are used to configure the CBOM-Repository:
| Environment Variable | Required | Default Value | Explanation |
|---|---|---|---|
APP_LOG_LEVEL | INFO | logger level, possible values: DEBUG, INFO, WARN, ERROR | |
APP_HTTP_PORT | 8080 | HTTP server port | |
APP_HTTP_PREFIX | /api | HTTP server handlers route prefix, mainly used to mount the CBOM Repository handlers under a different starting path | |
APP_S3_ACCESS_KEY | s3-compatible store access key | ||
APP_S3_SECRET_KEY | s3-compatible store secret key | ||
APP_S3_REGION | s3-compatible store Region | ||
APP_S3_ENDPOINT | s3-compatible store endpoint, leave empty for aws roles or default aws env. variables to take precedence | ||
APP_S3_BUCKET | bucket name | ||
APP_S3_USE_PATH_STYLE | true | Use s3 path style |
Content type
Image
Digest
sha256:203b7f2dd…
Size
11.5 MB
Last updated
2 months ago
docker pull czertainly/cbom-repository:develop-943b03a2714c8ef64e459b1206c95cba25a55135