Git Product home page Git Product logo

sbom-search's Introduction

sbom-search

Search your KSOC image SBOMs in multiple accounts for a specific package name.

How to download SBOM data

In each KSOC account you want to search, create an API token in Settings>API Tokens. Take note of the Access Key and Secret Access Key. You will also need the Account ID which can be found in the browser address bar.
https://app.ksoc.com/{TENANTID}/accounts/{ACCOUNTID}

Add on entry for each account in the file allaccounts.sh
./sbom.sh {accessKeyId1} {secretKeyId1} {accountId1}
./sbom.sh {accessKeyId2} {secretKeyId2} {accountId2}

Then run ./allaccounts.sh. For each account in allaccounts.sh, all the image SBOMs will be downloaded in a file in the local folder along with supporting files that contain the image data, a list of image resources, and list of image clusters.\

The file names are:
{ACCOUNT_ID}-{NAME}-{DIGEST}.sbom
{ACCOUNT_ID}-{NAME}-{DIGEST}.sbom.cluster.data
{ACCOUNT_ID}-{NAME}-{DIGEST}.sbom.images.data
{ACCOUNT_ID}-{NAME}-{DIGEST}.sbom.resource.data

How to search for packages in downloaded image SBOMs

Run search.sh and include one package name as a parameter.

Example:
search.sh curl

All the SBOMs will be searched and results will be seen in STOUT.

You can output the data to a CSV by redirecting STOUT.

Example:
search.sh curl > search_curl.csv

Output includes the following:

  • imagename
  • imagesource
  • imageversion
  • packagename
  • packageversion
  • workloadname
  • workloadtype
  • workloadnamespace
  • workloadcluster

Output

Example output below for curl:

imagename imagesource imageversion packagename packageversion workloadname workloadtype workloadnamespace workloadcluster
controller registry.k8s.io/ingress-nginx/ ["v1.6.4"] curl 7.87.0-r1 ingress-nginx-controller-86cb994656-7nf26 Pod ingress-nginx SFO3 PRD
controller registry.k8s.io/ingress-nginx/ ["v1.6.4"] curl 7.87.0-r1 ingress-nginx-controller-86cb994656-j68rk Pod ingress-nginx SFO3 PRD
controller registry.k8s.io/ingress-nginx/ ["v1.6.4"] curl 7.87.0-r1 ingress-nginx-controller-86cb994656-pbddb Pod ingress-nginx NYC1 PRD
controller registry.k8s.io/ingress-nginx/ ["v1.6.4"] curl 7.87.0-r1 ingress-nginx-controller-86cb994656-xmmj9 Pod ingress-nginx NYC1 PRD
controller registry.k8s.io/ingress-nginx/ ["v1.8.2"] curl 8.2.1-r0 ingress-nginx-controller-5dcc7dbd55-vf74z Pod kube-system EKS US-West-2 PRD
cpbridge docker.io/digitalocean/ ["1.25.1"] curl 7.88.1-10+deb12u1 cpc-bridge-proxy-2wk7r Pod kube-system Honeypot
cpbridge docker.io/digitalocean/ ["1.25.1"] curl 7.88.1-10+deb12u1 cpc-bridge-proxy-58dbp Pod kube-system NYC1 PRD
cpbridge docker.io/digitalocean/ ["1.25.1"] curl 7.88.1-10+deb12u1 cpc-bridge-proxy-9hzrd Pod kube-system Honeypot
cpbridge docker.io/digitalocean/ ["1.25.1"] curl 7.88.1-10+deb12u1 cpc-bridge-proxy-bw6dn Pod kube-system SFO3 PRD
cpbridge docker.io/digitalocean/ ["1.25.1"] curl 7.88.1-10+deb12u1 cpc-bridge-proxy-mgszs Pod kube-system SFO3 PRD

sbom-search's People

Contributors

jeffreyfriedman avatar ksoc-automator avatar

Stargazers

 avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Forkers

jrm16020

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.