Skip to main content

Manifests supported for SBOM generation by SCA

Table 13.1: Manifests supported for SBOM generation by SCA

LanguageManifests
Java/Kotlin/Scalapom.xml, ivy.xml, *.gradle, gradle.lockfile
JavaScript/TypeScriptpackage.json, package-lock.json, yarn.lock, pnpm-lock.yaml
Pythonsetup.py, Pipfile, Pipfile.lock, pyproject.toml, poetry.lock, requirements.txt, requirements.pip, requires.txt
C/C++conanfile.txt, conan.lock
Gogo.mod, go.sum
PHPcomposer.json, composer.lock
RubyGemfile, Gemfile.lock, *.gemspec
C#/VB.NET*.nuspec, packages.lock.json, Project.json, Project.lock.json, packages.config, paket.dependencies, paket.lock, *.csproj, *.fsproj, *.vbproj, project.assets.json, sln
Objective-C/SwiftPodfile, Podfile.lock, *.podspec
RustCargo.lock, Cargo.toml
Dartpubspec.yaml, pub.lock
Erlangrebar.config, rebar, rebar.lock