Source code

Since each programming language has its declaration files for the libraries being used, the SBOM engine only analyzes the files with these specific filenames to avoid false positives or performance downgrades.

Programming languageFile to check
RubyGemfile.lock lib package in tar.gz, gem format
Python

Pipfile.lock

poetry.lock

requirements*.txt

setup.py

pyproject.toml

lib package in tar.gz, egg, whl, zip format

PHPcomposer.lock lib package in zip format
NodeJS

package-lock.json

yarn.lock

pnpm-lock.yaml

Java

pom.xml

gradle.lockfile

*.jar

lib package in *.zip, *-src.zip, *-sources.zip, *.tar.gz, *-src.tar.gz, *-sources.tar.gz format

Gogo.mod
RustCargo.lock
Dartpubspec.lock
.NET

packages.lock.json

packages.config

.deps.json

dll

library in *.nupkg

Elixirmix.lock
SwiftPodfile.lock
C/C++ package managerconan.lock
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
On This Page
Source code