For the complete documentation index, see llms.txt. This page is also available as Markdown.

CycloneDX SBOM Generation

CycloneDX SBOM Generation is an open-source tool that automatically generates a Software Bill of Materials (SBOM) for your application.

Usage of CycloneDX SBOM Generation in Delivery Shield

  • Scans your application's source code or package manifests.

  • Detects dependencies across multiple programming languages and package managers.

  • Generates an SBOM in the standard CycloneDX format.

To Manage CycloneDX SBOM Generation:

  1. Navigate to Setup > Integrations.

  2. In the Artifact panel, click CycloneDX SBOM Generation.

  3. The CycloneDX SBOM Generation integration page is displayed.

  4. Click +New Account.

  5. In the popup that appears,

  6. Enable the Vulnerability Scan toggle button.

  7. Select the **Teams **and the corresponding **Environments **from the dropdown for which you want the integration to be available. The integration will be available for the selected teams and environment only.

[info] You can select up to 5 teams for the integration to be displayed.

  • An example is given below for reference:

  • In the example above,

    • if Team 1, Team 2, and Team 3 are selected, only applications associated with these teams can access the integration. Any applications belonging to other teams, such as Team 4, will not have access to this account.

  • Even if the user who created this account is also an admin for Team 4, the integration account remains restricted and is not available for Team 4.

  • Access to the account is strictly limited to the specified Teams and Environments selected during account creation.

  • For Organization Admins:

    • When an Organization Admin creates an account without selecting specific Teams and Environments, the account will be universally applicable, granting access to all teams and all environments by default.

  • For Team Admins with Multiple Teams:

    • If a Team Admin who manages multiple teams creates an account without specifying particular Teams and Environments, the account will only be accessible to the teams for which the logged-in user holds admin privileges.

  1. Click Save. The tool is connected.

  2. You can edit the entered values by clicking the Edit option as shown below:

  3. Enable or disable the Vulnerability Scan toggle button and click Update.

The new setting gets updated.

Last updated