> For the complete documentation index, see [llms.txt](https://docs.opsmx.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.opsmx.com/integrations/integrating-security-scanning-tools/cdxgen.md).

# CDXGEN

**CDXGen** is an open-source tool that automatically generates a **Software Bill of Materials (SBOM)** for your application. &#x20;

### Usage of CDXGEN in Delivery Shield

* Scans your application's source code or package manifests.
* Detects dependencies across multiple programming languages and package managers.
* Generates an SBOM in the standard CycloneDX format.

### To Manage CDXGEN:

1. Navigate to **Setup** > **Integrations**.
2. In the **Artifact** panel, click **CDXGEN**.

<figure><img src="/files/uxi2gpkpwrLBP5mG2k7b" alt=""><figcaption></figcaption></figure>

3. The CDXGEN integration page is displayed.
4. Click **+New Account**.&#x20;
5. In the popup that appears,&#x20;
   1. Enable the **Vulnerability Scan** toggle button. &#x20;

<figure><img src="/files/MPhs8gzEE6ZaSwGw9Vd3" alt=""><figcaption></figcaption></figure>

6. Select the **Teams** and the corresponding **Environments** from the dropdown for which you want the integration to be available. The integration will be available for the selected teams and environment only.&#x20;

{% hint style="info" %}
You can select up to 5 teams for the integration to be displayed.&#x20;
{% endhint %}

* An example is given below for reference:

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeuMZQzZsZQuulVdW9B9OuffNPoEXqbcpcAkYtKVyb7YiTQxbVIt1L4Gh-zshqX2J9MFKIat8x4oWFIGxdg3j1XVagyUNhUAlD_52soyMyd1cy53p6XiYi0LsTjIBfHcybRWl61?key=D9EXoOdGF7oYOBvYaW2GnRWJ" alt=""><figcaption></figcaption></figure>

* In the example above,&#x20;
  * if **Team 1**, **Team 2**, and **Team 3** are selected, only applications associated with these teams can access the integration. Any applications belonging to other teams, such as **Team 4**, will not have access to this account.
  * Even if the user who created this account is also an admin for **Team 4**, the integration account remains restricted and is not available for **Team 4**.&#x20;
  * Access to the account is strictly limited to the specified **Teams** and **Environments** selected during account creation.
* **For Organization Admins:**
  * When an **Organization Admin** creates an account without selecting specific **Teams** and **Environments**, the account will be universally applicable, granting access to **all teams** and **all environments** by default.
* **For Team Admins with Multiple Teams:**
  * If a **Team Admin** who manages multiple teams creates an account without specifying particular **Teams** and **Environments**, the account will only be accessible to the teams for which the logged-in user holds admin privileges.

7. Click **Save**. The tool is connected.&#x20;
8. You can edit the entered values by clicking the **Edit** option as shown below:

<figure><img src="/files/L5zdRW8f6ycyNLXfbRBJ" alt=""><figcaption></figcaption></figure>

9. Enable or disable the **Vulnerability Scan** toggle button and click **Update**.&#x20;

<figure><img src="/files/HRQDpBs0bD8BORwwLVlV" alt=""><figcaption></figcaption></figure>

The new setting gets updated.&#x20;

<br>
