Skip to content
ocx
install

SbomEntry (1 of 2)

SbomEntryclassdataclass#

Re-exported from ocx_sdk._resultsView source
class SbomEntry(predicate_type: str, verified: bool, shadowed: bool, subject_digest: str, referrer_digest: str, certificate_identity: str | None = None, certificate_oidc_issuer: str | None = None, signed_at: str | None = None, summary: SbomSummaryOut | None = None)

One SBOM document sbom listed (C-014).

Field list verified against sbom.rs:104-162.

Attributes

NameTypeDescription
predicate_typestrThe SBOM’s predicate type URI (CycloneDX, SPDX, …).
verifiedboolWhether a signature was verified over this document. False means it is attached raw, with no identity behind it — this is ocx policy, not a cosign or CycloneDX term.
shadowedboolWhether a platform-level SBOM of the same predicate_type supersedes this index-level one. Always present; False is a true claim, not an absence.
subject_digeststrThe manifest digest this SBOM describes.
referrer_digeststrThis SBOM document’s own digest. Not always a manifest digest — for a verified .att sidecar it is a layer blob digest (sbom.rs:128-148); feeding it to a manifest fetch 404s. Same caveat SignatureEntry/VerificationReport carry for their own referrer_digest.
certificate_identitystr | NoneThe Fulcio certificate’s identity, when verified and the signature is keyless.
certificate_oidc_issuerstr | NoneThe Fulcio certificate’s OIDC issuer, when verified and the signature is keyless.
signed_atstr | NoneWhen the signature was produced, as ocx spelled it, when verified.
summarySbomSummaryOut | NoneComponent counts, when the call carried --summary and this entry parsed successfully as CycloneDX 1.5-1.7 — see SbomSummaryOut. None otherwise; the listing itself still works without --summary, it just leaves this unpopulated.

certificate_identityattributeclass attributeinstance attribute#

certificate_identity: str | None = None

certificate_oidc_issuerattributeclass attributeinstance attribute#

certificate_oidc_issuer: str | None = None

predicate_typeattributeinstance attribute#

predicate_type: str

referrer_digestattributeinstance attribute#

referrer_digest: str

shadowedattributeinstance attribute#

shadowed: bool

signed_atattributeclass attributeinstance attribute#

signed_at: str | None = None

from_dictmethodclassmethod#

def from_dict(data: Mapping[str, Any]) -> SbomEntry

Build from one decoded entry of SbomListingReport.entries.