A scanner for IaC definitions, transferring them to TrustSource as input for better threat modeling
108
An SBOM tells you what is inside your software. ts-obom tells you what it runs as — and what it may reach once it does.
ts-obom reads your infrastructure as code and produces a CycloneDX
Operations BOM: every resource your project is deployed as, and the IAM
grants that connect them. Which function may write to which table. Which role
may read which bucket. Through which policy that permission was granted.
No cloud credentials. No terraform init. No agent in your account. It reads
the sources you already have in your repository, and it runs offline.
trustsource/ts-obom:latest| Front-end | Sources |
|---|---|
cloudformation | CloudFormation and AWS SAM templates |
terraform | Terraform and OpenTofu (.tf, .tofu, and their JSON variants) |
docker run --rm -v "$(pwd)":/workspace trustsource/ts-obom \
scan -f cyclonedx -o /workspace/obom.cdx.json /workspace
Content type
Image
Digest
sha256:ad488947d…
Size
55.7 MB
Last updated
7 days ago
docker pull trustsource/ts-obom