CRA Desk
Every generate step

Generating an SBOM for Go

The step below writes a CycloneDX JSON file in your own pipeline. The CRA Desk scan reads that file and turns it into a readiness report - it never generates one for you.

Run in CI:

go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest
cyclonedx-gomod mod -json -output sbom.json
Produces:
sbom.json
Format:
CycloneDX JSON
Generator documentation

The whole CI job

GitHub Actions

- uses: actions/checkout@v4
- run: go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest
- run: cyclonedx-gomod mod -json -output sbom.json
- uses: mmalinowski/cradesk-action@v1
  with:
    sbom-path: sbom.json

GitLab CI/CD

generate-sbom:
  script:
    - go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest
    - cyclonedx-gomod mod -json -output sbom.json

include:
  - component: gitlab.com/cradesk/scan/readiness@1
    inputs:
      sbom_path: sbom.json

Only the first step changes with your stack - the CRA Desk step after it is identical everywhere.

What goes wrong here

cyclonedx-gomod mod reads go.mod, which lists more than a binary actually links. Use cyclonedx-gomod app for what ships, at the cost of building it first.

What CRA Desk does with the result

Components from this build carry pkg:golang package URLs, which the watch matches against OSV's Go advisories when the SBOM arrives and again as new advisories land. Matching runs on every plan; e-mail alerts and the full match list are what a paid plan adds.

A generator that runs is not the same as coverage. Components with no purl, no version, or from an ecosystem outside the nine we watch are counted as gaps in every report rather than reported as clean.