- integrations
- Python
- ocx_sdk
SbomEntry (1 of 2)
SbomEntryclassdataclass#
Re-exported from
ocx_sdk._resultsView sourceclass SbomEntry(predicate_type: str, verified: bool, shadowed: bool, subject_digest: str, referrer_digest: str, certificate_identity: str | None = None, certificate_oidc_issuer: str | None = None, signed_at: str | None = None, summary: SbomSummaryOut | None = None)One SBOM document sbom listed (C-014).
Field list verified against sbom.rs:104-162.
Attributes
| Name | Type | Description |
|---|---|---|
predicate_type | str | The SBOM’s predicate type URI (CycloneDX, SPDX, …). |
verified | bool | Whether a signature was verified over this document.
False means it is attached raw, with no identity behind it —
this is ocx policy, not a cosign or CycloneDX term. |
shadowed | bool | Whether a platform-level SBOM of the same
predicate_type supersedes this index-level one. Always
present; False is a true claim, not an absence. |
subject_digest | str | The manifest digest this SBOM describes. |
referrer_digest | str | This SBOM document’s own digest. Not always a
manifest digest — for a verified .att sidecar it is a layer
blob digest (sbom.rs:128-148); feeding it to a manifest fetch
404s. Same caveat SignatureEntry/VerificationReport carry
for their own referrer_digest. |
certificate_identity | str | None | The Fulcio certificate’s identity, when
verified and the signature is keyless. |
certificate_oidc_issuer | str | None | The Fulcio certificate’s OIDC issuer, when
verified and the signature is keyless. |
signed_at | str | None | When the signature was produced, as ocx spelled it, when
verified. |
summary | SbomSummaryOut | None | Component counts, when the call carried --summary and
this entry parsed successfully as CycloneDX 1.5-1.7 — see
SbomSummaryOut. None otherwise; the listing itself still
works without --summary, it just leaves this unpopulated. |
certificate_identityattributeclass attributeinstance attribute#
certificate_identity: str | None = Nonecertificate_oidc_issuerattributeclass attributeinstance attribute#
certificate_oidc_issuer: str | None = Nonepredicate_typeattributeinstance attribute#
predicate_type: strreferrer_digestattributeinstance attribute#
referrer_digest: strshadowedattributeinstance attribute#
shadowed: boolsigned_atattributeclass attributeinstance attribute#
signed_at: str | None = None