Skip to content

v0.0.4

Choose a tag to compare

@hexdroid-support hexdroid-support released this 23 May 06:18

This release adds add-sbom command.

Uploading SBOMs

HexDroid CLI now provides two convenient methods for uploading your Software Bill of Materials (SBOMs): via standard input (
stdin) or directly from a file path.

Uploading via Standard Input (stdin)

This method is ideal for piping the output of another command directly as your SBOM data.

Example: To upload the dependency tree generated by a Gradle command as an SBOM:

./gradlew app:dependencies | java -jar hexdroid-cli.jar ota add-sbom --stdin --versionCode=1 --target=smart_oven --type="gradle"

Uploading from a File Path

Alternatively, you can specify the path to your SBOM file.

Example: To upload an AOSP pinned manifest file as an SBOM:

java -jar hexdroid-cli.jar ota add-sbom --versionCode=1 --target=smart_oven --file=/build/aosp/aosp_pinned_manifest.xml --type="aosp_manifest"

Learn more: https://hexdroid.com/changelog/sbom