Skip to content

add export command to convert SBOM into graph#70

Merged
Urist-McGit merged 5 commits intomainfrom
fm/graph-export
Oct 13, 2025
Merged

add export command to convert SBOM into graph#70
Urist-McGit merged 5 commits intomainfrom
fm/graph-export

Conversation

@fmoessbauer
Copy link
Member

Exporting the SBOM to a precise and annotated graph enables graph-tooling to further analyze and reason about it.

We add support to parse a debsbom generated SPDX and CycloneDX SBOM and convert that to graphml. The infrastructure is prepared to be easily extendable for other graph formats like GXL or dot.

@fmoessbauer
Copy link
Member Author

Depends on #65

@fmoessbauer fmoessbauer marked this pull request as draft October 10, 2025 09:11
@fmoessbauer fmoessbauer force-pushed the fm/graph-export branch 4 times, most recently from 53338d3 to 57e28f7 Compare October 13, 2025 08:14
Exporting the SBOM to a precise and annotated graph enables
graph-tooling to further analyze and reason about it.

We add support to parse a debsbom generated SPDX and CycloneDX SBOM and
convert that to graphml. The infrastructure is prepared to be easily
extendable for other graph formats like GXL or dot.

Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
@fmoessbauer fmoessbauer marked this pull request as ready for review October 13, 2025 10:21
@Urist-McGit Urist-McGit merged commit 22c2970 into main Oct 13, 2025
11 checks passed
@Urist-McGit Urist-McGit deleted the fm/graph-export branch October 13, 2025 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants