/** * CycloneDX 1.5 SBOM builder (audit #83, milestone 4). * * Hand-rolled minimal SBOM. No external dependencies — keeps the * SDK tree small and the output deterministic. Covers: * * - `bomFormat`: 'CycloneDX' * - `specVersion`: '1.5' * - `serialNumber`: `urn:uuid:` for tracking * - `metadata.timestamp`: ISO 8601 instant at generation * - `metadata.tools`: the SDK version (so SBOMs are themselves * traceable to a Bizar release) * - `metadata.component`: the root package (Bizar) with version + * purl * - `components[]`: every runtime dependency, with name + version + * purl + scope (required for the `bizar install` lock) * - `dependencies[]`: the runtime dependency graph * * Inputs are package.json files. No `npm install` is invoked. * * The output is a JSON object suitable for `JSON.stringify(sbom, null, 2)` * and `writeFileSync(out, …)` at release time. */ export interface SbomComponent { readonly type: "library" | "application" | "framework"; readonly "bom-ref": string; readonly name: string; readonly version: string; readonly purl: string; readonly scope?: "required" | "optional" | "dev"; } export interface SbomMetadata { readonly timestamp: string; readonly tools: ReadonlyArray<{ readonly vendor: string; readonly name: string; readonly version: string; }>; readonly component: SbomComponent; } export interface SbomDependencyEntry { readonly ref: string; readonly dependsOn: ReadonlyArray; } export interface Sbom { readonly bomFormat: "CycloneDX"; readonly specVersion: "1.5"; readonly serialNumber: string; readonly version: number; readonly metadata: SbomMetadata; readonly components: ReadonlyArray; readonly dependencies: ReadonlyArray; } export interface SbomInput { /** The root package name (e.g. "@polderlabs/bizar"). */ readonly name: string; /** The root package version. */ readonly version: string; /** The SDK version that produced this SBOM (for traceability). */ readonly toolsVersion: string; /** Runtime dependencies as `{ name, version, scope? }`. */ readonly runtimeDependencies: ReadonlyArray<{ readonly name: string; readonly version: string; readonly scope?: "required" | "optional"; }>; /** Optional dev dependencies — kept separate so the SBOM does not bloat. */ readonly devDependencies?: ReadonlyArray<{ readonly name: string; readonly version: string; }>; /** Generation timestamp; ISO 8601. Defaults to `new Date().toISOString()`. */ readonly timestamp?: string; } /** Build a CycloneDX 1.5 SBOM from `SbomInput`. */ export declare function buildSbom(input: SbomInput): Sbom; //# sourceMappingURL=sbom.d.ts.map