sbom-filter
v1.0.0
Published
Filter CycloneDX SBOM to components reachable from given root packages
Readme
sbom-filter
Filter a CycloneDX JSON SBOM to only components reachable from given root packages.
Usage
npx sbom-filter <sbom.json> <pkg1> <pkg2> ...Scoped packages are supported:
npx sbom-filter sbom-front.json vue pinia @vuepic/vue-datepicker > sbom-vuejs.jsonOutput is written to stdout.
How it works
- Finds root components by name or
@scope/name(matched via purl) - Walks the
dependenciesgraph recursively from each root - Filters
componentsanddependenciesto only reachable entries
