Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Release: ServiceM8 Webform Integration 1.2.1 — Minor update available for module servicem8_webform (1.2.1). Release: PostfixAdmin 1.0.0 — Initial release available for module postfix_admin (1.0.0)! Release: ip_analyser 1.0.3 — Minor update available for module ip_analyser (1.0.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

Drubom - Drupal Bill of Materials

What is Drubom ?

DruBOM, short for Drupal Bill of Materials, is a module specifically designed for installations. It leverages the capabilities of Anchore Grype and Anchore Syft to produce a comprehensive software bill of materials (SBOM) for a Drupal site. This includes PHP dependencies and libraries from other ecosystems, such as JavaScript dependencies.

What is an SBOM and why it's crucial

A Software Bill of Materials (SBOM) is a list of all the components of a software application. It includes information such as the name of each element, the version number, and any dependencies it has on other parts.

An SBOM aims to provide transparency and accountability in the software supply chain, helping organizations identify and address potential security vulnerabilities and other risks. By understanding precisely what software components are included in an application, organizations can take steps to ensure that they are up-to-date, properly licensed, and free from known security vulnerabilities.

This is particularly important in today's digital landscape, where cyber threats are evolving rapidly, and software applications are increasingly complex and interconnected. In short, an SBOM is a critical tool for managing software risk and ensuring the security and integrity of your organization's digital assets.

How it works

It is simple; it can be used with Drush or the admin console. You need this module and the Syft and/or Grype binaries installed, which are reachable from PHP.

You can find more detailed instructions on how to use it in the README file of the source code.

The module is currently in active development, and changes may happen rapidly. You are encouraged to collaborate using any means you prefer, from issues to testing to new features.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Oct 2023
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Dormant

Releases

Version Type Core Release date
1.0.x-dev Dev Oct 11, 2023