Plan and implement work described in a GitHub issue, including verification, documentation, and a PR that closes the issue.
日本語の概要は準備中です。原文の説明を表示しています。
Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. Covers SBOM generation with Syft, license resolution via public registries, and CSV export for compliance review. Trigger keywords - SBOM, sbom, bill of materials, license audit, license resolution, generate sbom, sbom csv, dependency license, supply chain, license scan.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Generate CycloneDX SBOMs, resolve missing licenses, and export to CSV for compliance review.
The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft, resolves missing or hash-based licenses by querying public registries (crates.io, npm, PyPI), and exports the results to CSV for stakeholder review.
SBOMs are release artifacts only -- they are generated on demand and not committed to the repository. Output lands in deploy/sbom/output/ (gitignored).
Pushed gateway, sandbox, and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.
mise install has been run (installs Syft and other tools)BuildKit uses its default Syft scanner and attaches one SPDX document per platform. Read one without pulling the image:
docker buildx imagetools inspect ghcr.io/nvidia/openshell/gateway:latest \
--format '{{ json (index .SBOM "linux/amd64").SPDX }}'
Validate the final attestation, requiring a Cargo package for an auditable image:
tasks/scripts/verify-image-sbom.sh ghcr.io/nvidia/openshell/gateway:latest --require-cargo
Opt into auditable metadata when staging a local image binary:
OPENSHELL_AUDITABLE=1 PREBUILT_ARCH=amd64 \
tasks/scripts/stage-prebuilt-binaries.sh gateway
Scan the staged binary rather than the source tree:
mise x -- syft \
"file:deploy/docker/.build/prebuilt-binaries/amd64/openshell-gateway" \
-o cyclonedx-json
This output is limited to packages Syft discovers from that binary. Use
mise run sbom for the broader source-tree license-compliance inventory.
mise run sbom
This single command chains three stages:
sbom:generate): Syft scans the workspace source tree and produces a CycloneDX JSON SBOMsbom:resolve): Public registry APIs fill in missing or hash-based licenses in the JSONsbom:csv): JSON SBOMs are converted to CSV for reviewOutput directory: deploy/sbom/output/
After running, the user can find:
deploy/sbom/output/*.cdx.json -- full CycloneDX SBOMsdeploy/sbom/output/*.csv -- CSV exports ready for spreadsheet reviewRun stages independently when debugging or iterating:
mise run sbom:generate # Generate JSON SBOMs only (requires Syft)
mise run sbom:resolve # Resolve licenses in existing JSONs (queries APIs)
mise run sbom:csv # Convert existing JSONs to CSV
mise run sbom:check
Reports unresolved licenses without failing. Intended for PR CI as a non-blocking advisory check. Requires that SBOMs have already been generated (mise run sbom:generate).
The Python scripts accept explicit file paths, so they can process SBOMs from any source (e.g., NVIDIA nSpect pipeline output):
uv run python deploy/sbom/resolve_licenses.py /path/to/external-sbom.json
uv run python deploy/sbom/sbom_to_csv.py /path/to/external-sbom.json
The resolver queries these public registries:
| Registry | Package URL prefix | Method |
|---|---|---|
| crates.io | pkg:cargo/* | REST API |
| npm | pkg:npm/* | Registry API |
| PyPI | pkg:pypi/* | JSON API |
| Go modules | pkg:golang/* | Known license map (no API) |
| Debian/Ubuntu | pkg:deb/* | Known license map |
Components from private registries (e.g., @openclaw/* npm packages) are not resolved and will appear in the "unresolved" report.
| Pattern | Description |
|---|---|
deploy/sbom/output/openshell-source-{version}.cdx.json | CycloneDX JSON SBOM |
deploy/sbom/output/openshell-source-{version}.csv | CSV export (name, version, type, purl, licenses, bom-ref) |
| File | Purpose |
|---|---|
deploy/sbom/resolve_licenses.py | License resolution script |
deploy/sbom/sbom_to_csv.py | JSON-to-CSV converter |
tasks/sbom.toml | Mise task definitions |
mise.toml | Syft tool definition (under [tools]) |
| Task | Command |
|---|---|
| Full pipeline | mise run sbom |
| Generate only | mise run sbom:generate |
| Resolve licenses | mise run sbom:resolve |
| Export CSV | mise run sbom:csv |
| CI license check | mise run sbom:check |
| Process external SBOM | uv run python deploy/sbom/resolve_licenses.py <file> |
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Plan and implement work described in a GitHub issue, including verification, documentation, and a PR that closes the issue.
日本語の概要は準備中です。原文の説明を表示しています。
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64. Use when working on Windows compilation, `windows:*` mise tasks, unsupported Windows compute-driver contracts, or Windows build reports. This skill does not implement Docker, Kubernetes, Podman, VM, MXC driver, policy translation, MSI, service, or supervisor runtime support on Windows.
日本語の概要は準備中です。原文の説明を表示しています。
Create GitHub issues using the gh CLI. Use when the user wants to create a new issue, report a bug, request a feature, or create a task in GitHub. Trigger keywords - create issue, new issue, file bug, report bug, feature request, github issue.
日本語の概要は準備中です。原文の説明を表示しています。
Create GitHub pull requests using the gh CLI. Use when the user wants to create a new PR, submit code for review, or open a pull request. Trigger keywords - create PR, pull request, new PR, submit for review, code review.
日本語の概要は準備中です。原文の説明を表示しています。
Create OpenShell RFC proposals in rfc/ from a design request. Use when the user asks to write, draft, start, create, or update an RFC, Request for Comments, architecture proposal, API proposal, process proposal, or cross-cutting design proposal that should follow the OpenShell RFC process and template.
日本語の概要は準備中です。原文の説明を表示しています。
Investigate an OpenShell problem and create a structured issue with technical findings for human disposition.
日本語の概要は準備中です。原文の説明を表示しています。