Import / Export
CBOM supports standards-compliant export for supply chain integration and multiple import paths for environments where sensors can’t push directly to the API.
Export
Section titled “Export”CycloneDX v1.6 CBOM
Section titled “CycloneDX v1.6 CBOM”Exports your full cryptographic inventory as a CycloneDX v1.6 JSON document. The export includes:
bomFormat: "CycloneDX",specVersion: "1.6"- Unique serial number (URN UUID)
- Every asset as a
cryptographic-assetcomponent with:algorithmProperties(primitive, family, curve, mode, OID, NIST quantum security level)certificateProperties(subject, issuer, serial, validity, extensions, fingerprint)relatedCryptoMaterialProperties(type, size, format, state)protocolProperties(version, cipher suites)
dependenciessection mapping issuer chains, key pairs, and keystore containment- BOM-Link URNs for cross-referencing with SBOMs
Use this for compliance reporting, supply chain attestations, or integration with other security tools.
Raw JSON
Section titled “Raw JSON”Exports all assets in CBOM’s internal format. Useful for custom processing, scripting, or backup.
Import
Section titled “Import”CycloneDX CBOM Import
Section titled “CycloneDX CBOM Import”Upload a CycloneDX CBOM JSON from external tools:
- cbomkit-theia — IBM’s open-source CBOM scanner
- cdxgen — CycloneDX generator
- IBM Quantum Safe Explorer
- Any CycloneDX v1.4+ compliant CBOM generator
Imported assets are ingested into the unified inventory with full quantum risk classification, relationship linking, and analytics — treated identically to sensor-discovered assets.
Visualize Without Importing
Section titled “Visualize Without Importing”Drag and drop any CycloneDX JSON to visualize its contents without modifying your inventory. Useful for reviewing external CBOMs before deciding to import.
Offline / Air-Gapped Import
Section titled “Offline / Air-Gapped Import”For environments where sensors cannot reach the API over the network:
Workflow
Section titled “Workflow”- Run the sensor in offline mode on the air-gapped machine:
Terminal window java -jar cbom-sensor.jar scan --config=config.yml --output=results.json - Transfer the results file via USB or secure file transfer
- Upload the file through the Import/Export page
Accepted Formats
Section titled “Accepted Formats”- Single
.json— one scan result file - Batch
.zip— multiple JSON scan results in a ZIP archive
Each file is processed through the same ingestion pipeline as live sensor data — deduplication, risk classification, and relationship linking all apply.
Batch Import Results
Section titled “Batch Import Results”After uploading a ZIP, you’ll see a per-file breakdown: created count, updated count, and status for each JSON file in the archive.
CI/CD Pipeline Import
Section titled “CI/CD Pipeline Import”For automated import from CI/CD pipelines, use the API directly:
curl -X POST https://cbom.yourcompany.com/api/v1/import/source-scan \ -H "Authorization: Bearer YOUR_TOKEN" \ -H "Content-Type: application/json" \ -d @scan-results.jsonThe payload should include a scannerType, hostname, and assets array.
Related
Section titled “Related”- Inventory — Browse imported and discovered assets
- API Reference — Import endpoint documentation