iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
sbomnix is a command-line tool for generating software bills of materials (SBOMs) from a Nix flake reference or store path. It can export CycloneDX JSON and SPDX JSON, and its documented example also produces CSV. The key choice is scope: the default runtime view requires the target to be built, while --buildtime reports the derivation’s build-time dependency closure without building the target.
What sbomnix does
The sbomnix README describes the tool as generating an SBOM from a Nix flake reference or store path. An SBOM is a structured inventory of software components and related metadata; it can support review, compliance work, and supply-chain analysis, but it is only as complete and accurate as the input and the available component information.
sbomnix is part of a broader repository of Nix software-supply-chain tools. The project also includes tools for dependency graphs, vulnerability scanning, outdated dependency checks, and provenance. For exporting dependency inventories, sbomnix’s documented primary formats are CycloneDX JSON and SPDX JSON.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Choose a flake reference or store path
Use a flake reference when metadata matters
A flake reference gives sbomnix context for finding the nixpkgs source associated with the target. For ordinary flake targets, the tool follows the flake lock graph to locate pinned nixpkgs; for a NixOS toplevel flakeref, it uses the evaluated configuration’s package set. This allows enrichment with information such as descriptions, licenses, maintainers, and homepage links when that metadata is available. The project recommends flake references when nixpkgs metadata enrichment is desired. See the metadata-enrichment guide.
#1 Best Overall
Use a store path when that is the artifact you have
A store path, such as /nix/store/…, can be used directly, as can a result symlink. But the store path does not identify which nixpkgs source produced it, so sbomnix skips nixpkgs metadata enrichment for this input. The SBOM can still describe components from the available Nix data; do not assume it will include nixpkgs-derived license, maintainer, or homepage information.
Install or run sbomnix
Nix must be available on your PATH. For flake-based use, the README demonstrates running the tool without a separate installation:
nix run github:tiiuae/sbomnix#sbomnix -- --help
For direct, non-flake use, the project requires a modern Nix with nix-command and --json-format 1. If you clone the project to work on it, the documented development-shell command is:
Recommended Free Tools
Rank #2
nix develop
Generate an SBOM from a Nix target
The README’s example targets wget from the nixpkgs unstable branch and writes CycloneDX JSON, SPDX JSON, and CSV files:
nix run github:tiiuae/sbomnix#sbomnix --
--flake github:NixOS/nixpkgs/nixos-unstable#wget
--sbom sbom.cdx.json
--spdx sbom.spdx.json
--csv sbom.csv
Substitute your own flake reference or store path for the example target. The output filenames are choices in this invocation, not fixed names required by the tool. For command-specific options in the installed version, run the documented --help command.
Choose runtime or build-time dependencies
These scopes answer different inventory questions; one is not a substitute for the other. sbomnix reports runtime dependencies by default. Use --buildtime when you want the derivation’s build-time dependency closure instead.
| Scope | What it represents | Does the target need to be built? | When it helps |
|---|---|---|---|
| Runtime (default) | References captured in the built output: dependencies needed by the resulting software at runtime. | Yes. The target must be built so its runtime closure can be determined. | Inventorying what the built output references or needs to run. |
Build-time (--buildtime) |
Store paths needed to reproduce the derivation’s build, including build tools and compilers. | No. Evaluating this closure does not require building the target. | Examining the toolchain and dependencies involved in producing the package. |
The runtime result depends on the built output, so this mode may incur the target’s build cost. The build-time closure avoids building the target, but it describes the build environment rather than the software’s runtime requirements.
Why metadata or identifiers may be missing or uncertain
Metadata depends on input context
When a flake reference provides nixpkgs context, sbomnix can look up nixpkgs metadata. A store path alone does not supply that source identity, and enrichment is therefore skipped. A missing description, license, maintainer, or homepage does not by itself mean the component is absent from the SBOM; it can mean the relevant metadata was unavailable from the input context.
Identity matching is stricter than a name match
Names, package names (pnames), and versions are lookup hints, not proof that a metadata record describes a component. The metadata helper accepts a result only if its derivation path (drvPath) or output path (outPath) exactly matches an SBOM component. This identity check helps avoid attaching metadata based only on a similar name or version.
Rank #4
CPEs can be exact or heuristic
When nixpkgs supplies an exact CPE identifier, sbomnix prefers it. If one is unavailable, heuristic matching can be used as a fallback; that is less certain than an exact source identifier and can be disabled. The README also notes that failure to access the CPE dictionary can result in less accurate fallback identifiers unless strict dictionary behavior is requested. Treat heuristic CPEs as candidates to review, not authoritative proof of identity.
Explicit PURLs have limitations
The project documents experimental support for an explicit PURL in derivation JSON. If meta.identifiers.purl is present, sbomnix prefers that singular value over a generated name-and-version PURL and normalizes it for export. The tool does not validate that an explicitly supplied PURL truly identifies the package, and the project notes a limitation for multi-output or grouped components. This is an implementation option, not a guarantee that every Nix package provides an explicit PURL.
How sbomnix fits with other Nix SBOM approaches
Two related projects take different integration approaches. nix-sbom-helper is described as tooling for standard Nix and flakes that exposes sbomnix-generated SBOMs as Nix outputs. Bombon describes generating CycloneDX v1.7 SBOMs for Nix packages. These descriptions establish differences in integration and documented format scope, not a comprehensive comparison of quality, metadata completeness, or supported dependency scopes. Choose based on whether a standalone command or Nix-project output integration suits your workflow, and verify each tool’s current documentation for the exact formats and scope you require.
Best Value
Project version context
The GitHub releases page lists v1.8.0. Its release notes describe a move by sbomnix and nixgraph to structured Nix data sources, removal of legacy fallback paths, and improvements to flake-reference handling and metadata enrichment, including component-identity lookup and preference for nixpkgs CPE data. The rendered entry shows “09 Jun 09:02” without a year, so that display alone does not establish the release year.
Automating SBOM-based checks
If you need recurring supply-chain checks rather than a one-time inventory, the project README points to a reusable GitHub Action and a local CLI for automating daily vulnerability scans for Nix flake projects. That is a related workflow; generating an SBOM with sbomnix alone does not mean a vulnerability scan has been performed. For broader context on exporting SBOMs, GitHub documents its own dependency-export workflows in its SBOM export guidance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

