Binarly · Arazzo Workflow
Generate supply-chain compliance artifacts with Binarly
Version 1.0.0
For a scanned image, export the full set of supply-chain assurance artifacts — CycloneDX and SPDX SBOMs, an OpenVEX VEX, a CBOM, and a findings report — for procurement and regulatory evidence.
View Spec
View on GitHub
CompanySecurityFirmware SecuritySupply Chain SecurityVulnerability ManagementSBOMBinary AnalysisPost-Quantum CryptographyUEFIDevSecOpsArazzoWorkflows
Provider
Workflows
generateComplianceArtifacts
Export SBOM, VEX, CBOM, and findings for an image.
1
sbomCycloneDX
GetSbomReportCycloneDX
Export the CycloneDX SBOM for the image.
2
sbomSPDX
GetSbomReportSPDX
Export the SPDX SBOM for the image.
3
vexOpenVEX
GetVexReportOpenVEX
Export the OpenVEX VEX document (exploitability status).
4
cbom
GetCbomReport
Export the CycloneDX CBOM (cryptographic bill of materials).
5
findingsJson
ImageFindingsReportJson
Export the machine-readable findings report.