Have a look at GitHub - tiiuae/sbomnix: A suite of utilities to help with software supply chain challenges on nix targets or GitHub - nikstur/bombon: Nix CycloneDX Software Bills of Materials (SBOMs) - there is a bit more discussion at How to do vulnerability scanning with Nix SBOMS?
1 Like