{"_id":"@amberfly/sbom-report","_rev":"2-46562d90d535a97b02db5a008c08e7d6","name":"@amberfly/sbom-report","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@amberfly/sbom-report","version":"1.0.0","keywords":["sbom","spdx","software-bill-of-materials","license","security","report","syft","grype","vulnerability","cve","html-report","supply-chain"],"author":"","license":"MIT","_id":"@amberfly/sbom-report@1.0.0","maintainers":[{"name":"vengeruk","email":"guy.pritchard@outlook.com"}],"homepage":"https://github.com/guypritchard/sbom-report#readme","bugs":{"url":"https://github.com/guypritchard/sbom-report/issues"},"bin":{"sbom-report":"bin/sbom-report.js"},"dist":{"shasum":"258cc479e4533a3a48106b16d89d5534408422b6","tarball":"https://registry.npmjs.org/@amberfly/sbom-report/-/sbom-report-1.0.0.tgz","fileCount":4,"integrity":"sha512-1YA2470VSwkSbIoRn7pOGvQwkrPxosWVyApTQcU+ONDcu7Gs2FLIeLR89o0hLQHlLyFTiynHChJDHL8DPVS+Ag==","signatures":[{"sig":"MEUCIDgZvQyJYt5HtJle8s2k/ZFaSc/fJTvRHHYXClFSlqTxAiEAi/fj+PjlhmVMfxkKN7iB3VP6Yhu3YMvmbX31cTT7MPk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":94449},"main":"bin/sbom-report.js","engines":{"node":">=14.0.0"},"gitHead":"11b9008e2ff5923ece2e6c2035eadc564fe8187a","scripts":{"test":"node test/sbom-report.test.js"},"_npmUser":{"name":"vengeruk","email":"guy.pritchard@outlook.com"},"repository":{"url":"git+https://github.com/guypritchard/sbom-report.git","type":"git"},"_npmVersion":"10.9.4","description":"Zero-dependency CLI tool that generates self-contained static HTML reports from SPDX JSON SBOMs with optional Grype vulnerability overlay. For teams using Syft and Grype who want beautiful reports without the rest of the toolchain.","directories":{},"_nodeVersion":"22.21.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/sbom-report_1.0.0_1771260868394_0.24096098834664414","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@amberfly/sbom-report","version":"1.0.1","description":"Zero-dependency CLI tool that generates self-contained static HTML reports from SPDX JSON SBOMs with optional Grype vulnerability overlay. For teams using Syft and Grype who want beautiful reports without the rest of the toolchain.","main":"bin/sbom-report.js","bin":{"sbom-report":"bin/sbom-report.js"},"scripts":{"test":"node test/sbom-report.test.js"},"keywords":["sbom","spdx","software-bill-of-materials","license","security","report","syft","grype","vulnerability","cve","html-report","supply-chain"],"repository":{"type":"git","url":"git+https://github.com/guypritchard/sbom-report.git"},"homepage":"https://github.com/guypritchard/sbom-report#readme","bugs":{"url":"https://github.com/guypritchard/sbom-report/issues"},"author":"","license":"MIT","engines":{"node":">=14.0.0"},"dependencies":{},"_id":"@amberfly/sbom-report@1.0.1","gitHead":"a0475a57feca9a8405077e4cf9b5fb6ba48883c2","_nodeVersion":"20.20.0","_npmVersion":"10.8.2","dist":{"integrity":"sha512-+EMgRU+Ehvfahzdxx0Q72yDdan410CO34vy/SMJH4nrR53KlsoEHx3upv1qZttLT+44lJRgZZaO0jYl0sWxSyg==","shasum":"ef054ade0dec587d4f4a0318863dbdd5f6030b35","tarball":"https://registry.npmjs.org/@amberfly/sbom-report/-/sbom-report-1.0.1.tgz","fileCount":4,"unpackedSize":92678,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@amberfly%2fsbom-report@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICrVpbkyijMvY9C+9bBHWP/HiS0c7LM+bj5r2Eb9FrcTAiEAh6G8PThtK4VVm+B8Jx60s5CdYxWy6Z0cq4AjIPB7xN0="}]},"_npmUser":{"name":"vengeruk","email":"guy.pritchard@outlook.com"},"directories":{},"maintainers":[{"name":"vengeruk","email":"guy.pritchard@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sbom-report_1.0.1_1771261757055_0.645810074465897"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-16T16:54:28.281Z","modified":"2026-02-16T17:09:17.798Z","1.0.0":"2026-02-16T16:54:28.551Z","1.0.1":"2026-02-16T17:09:17.199Z"},"bugs":{"url":"https://github.com/guypritchard/sbom-report/issues"},"license":"MIT","homepage":"https://github.com/guypritchard/sbom-report#readme","keywords":["sbom","spdx","software-bill-of-materials","license","security","report","syft","grype","vulnerability","cve","html-report","supply-chain"],"repository":{"type":"git","url":"git+https://github.com/guypritchard/sbom-report.git"},"description":"Zero-dependency CLI tool that generates self-contained static HTML reports from SPDX JSON SBOMs with optional Grype vulnerability overlay. For teams using Syft and Grype who want beautiful reports without the rest of the toolchain.","maintainers":[{"name":"vengeruk","email":"guy.pritchard@outlook.com"}],"readme":"# sbom-report\n\nZero-dependency CLI tool that generates **self-contained static HTML reports** from [SPDX](https://spdx.dev/) JSON SBOMs, with an optional [Grype](https://github.com/anchore/grype) vulnerability overlay.\n\nBuilt for teams using **[Syft](https://github.com/anchore/syft)** and **[Grype](https://github.com/anchore/grype)** who want clean, interactive reports without the rest of the enterprise toolchain.\n\n![SBOM Report Screenshot](docs/image.png)\n\n## Features\n\n- **Zero dependencies** — uses only Node.js built-ins (`fs`, `path`)\n- **Self-contained HTML** — single file output, no external resources, works offline\n- **SPDX JSON → interactive report** in one command\n- **Optional vulnerability overlay** — accepts pre-generated Grype JSON output via `--vulns`\n- **License analysis** — classifies packages as permissive, weak copyleft, copyleft, restrictive, or unknown\n- **Package origin detection** — separates container/OS packages from application dependencies\n- **Clickable dashboards** — severity cards, license cards, and package cards filter the tables\n- **Dark/light theme** — dark by default, `--light` for print-friendly output\n- **Build metadata** — extracts commit hash, branch, and build number from SPDX `comment` field\n- **Registry links** — direct links to npm, PyPI, Maven Central, NuGet, OSV, NVD, deps.dev\n\n## Quick Start\n\n### Install globally\n\n```bash\nnpm install -g sbom-report\n```\n\n### Or use with npx (no install)\n\n```bash\nnpx sbom-report my-app.spdx.json\n```\n\n## Usage\n\n### 1. Generate an SBOM with Syft\n\n```bash\n# Scan a container image\nsyft <image> -o spdx-json > my-app.spdx.json\n\n# Scan a directory\nsyft dir:./my-project -o spdx-json > my-app.spdx.json\n```\n\n### 2. Generate the report\n\n```bash\n# Basic report (dark theme, output to my-app-report.html)\nsbom-report my-app.spdx.json\n\n# Custom output path and title\nsbom-report my-app.spdx.json -o report.html -t \"Release 3.2 Audit\"\n\n# Light theme for printing/sharing\nsbom-report my-app.spdx.json --light\n```\n\n### 3. Add vulnerability data (optional)\n\nRun Grype separately to generate a vulnerability scan, then pass it in:\n\n```bash\n# Scan with Grype\ngrype sbom:my-app.spdx.json -o json > vulnerabilities.json\n\n# Generate report with vulnerability overlay\nsbom-report my-app.spdx.json --vulns vulnerabilities.json\n```\n\n## CLI Reference\n\n```\nsbom-report <input.spdx.json> [options]\n\nOptions:\n  -o, --output <file>   Output HTML file path (default: <input>-report.html)\n  -t, --title  <title>  Custom report title\n  --vulns <file>        Grype JSON vulnerability scan results to overlay\n  --dark                Force dark theme (default)\n  --light               Force light theme\n  -h, --help            Show help\n```\n\n## Report Sections\n\n| Section | Description |\n|---|---|\n| **Vulnerability Banner** | Total CVE count with severity breakdown (only with `--vulns`) |\n| **Vulnerability Dashboard** | Clickable severity cards: Critical, High, Medium, Low, Negligible, Fixable |\n| **SBOM Facts** | Clickable cards: Total Packages, Container/OS, Application, Copyleft, Unknown License, CPE count |\n| **Document Information** | SPDX metadata, creators, namespace, commit/branch/build info |\n| **Package Origin** | Stacked bar chart showing container vs application package distribution |\n| **Vulnerabilities Table** | Searchable, filterable, sortable table with expandable CVE details (only with `--vulns`) |\n| **CVE Lookup** | CPE-based links to NVD and OSV grouped by origin |\n| **License Analysis** | License risk classification cards, alerts, distribution chart |\n| **All Packages** | Full searchable, sortable package table with expandable details |\n\n## Pipeline Integration\n\n### Azure DevOps\n\n```yaml\nsteps:\n  - script: |\n      # Install tools\n      curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b /usr/local/bin\n      curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin\n\n      # Generate SBOM\n      syft $(imageRef) -o spdx-json > sbom.spdx.json\n\n      # Scan for vulnerabilities\n      grype sbom:sbom.spdx.json -o json > vulnerabilities.json\n\n      # Generate report\n      npx sbom-report sbom.spdx.json --vulns vulnerabilities.json -o $(Build.ArtifactStagingDirectory)/sbom-report.html\n    displayName: 'Generate SBOM Report'\n\n  - publish: $(Build.ArtifactStagingDirectory)/sbom-report.html\n    artifact: sbom-report\n```\n\n### GitHub Actions\n\n```yaml\n- name: Generate SBOM Report\n  run: |\n    # Install Syft & Grype\n    curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b /usr/local/bin\n    curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin\n\n    # Generate SBOM and scan\n    syft ${{ env.IMAGE_REF }} -o spdx-json > sbom.spdx.json\n    grype sbom:sbom.spdx.json -o json > vulnerabilities.json\n\n    # Generate report\n    npx sbom-report sbom.spdx.json --vulns vulnerabilities.json -o sbom-report.html\n\n- uses: actions/upload-artifact@v4\n  with:\n    name: sbom-report\n    path: sbom-report.html\n```\n\n## Prerequisites\n\n- **Node.js** >= 14.0.0\n- **Syft** — to generate SPDX JSON SBOMs ([install](https://github.com/anchore/syft#installation))\n- **Grype** *(optional)* — to generate vulnerability scan JSON ([install](https://github.com/anchore/grype#installation))\n\n> **Note:** This tool does **not** invoke Syft or Grype. It only reads their JSON output files. You run the scanners yourself, giving you full control over versions, databases, and scan configuration.\n\n## Why?\n\nEnterprise SBOM platforms are heavy — they need databases, APIs, dashboards, and licenses. Sometimes you just want:\n\n1. Run `syft` to get an SBOM\n2. Run `grype` to get vulnerabilities\n3. Get a **single HTML file** you can open in a browser, attach to a ticket, or publish as a build artifact\n\nThat's what this tool does. Nothing more.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}