List all installed packages+version for audit purposes

Have a look at GitHub - tiiuae/sbomnix: A suite of utilities to help with software supply chain challenges on nix targets or GitHub - nikstur/bombon: Nix CycloneDX Software Bills of Materials (SBOMs) - there is a bit more discussion at How to do vulnerability scanning with Nix SBOMS?

1 Like