Download SBOMs directly from the web app

You can now download auto-generated Software Bills of Materials (SBOMs) for your Docker and OCI images directly from the Cloudsmith web app. This allows you to instantly export supply chain data for use in analysis tools or alongside release documentation.

Previously, SBOMs generated by Cloudsmith were only accessible via the packages API. Instead of scripting an API call to retrieve the manifest for a specific image, you can now grab the CycloneDX file with a single click, making SBOMs accessible to a broader range of users.

How it works

  1. Navigate to an image in Cloudsmith
  2. Click the Actions menu → "Download SBOM"
Download SBOMs directly from the web app
Download SBOMs directly from the web app

Technical notes

  • Downloads are provided in CycloneDX format.
  • This feature applies only to SBOMs automatically generated by Cloudsmith during the container image synchronization process.
  • Cloudsmith automatically generates SBOMs for Docker V2 and OCI V1 images.

​​This feature is live and available immediately for all Docker images. If you have any questions or feedback, please contact us.

Keep up to date with our monthly product bulletin