Software Bill of Materials and License Texts
This page explains how to work with Software Bill of Materials (SBOMs) and license information for Airlock Microgateway container images. It describes the SBOM format, how to retrieve and verify SBOM attestations with Cosign, and where to find and extract license texts from the images.
Software Bill of Materials
Airlock Microgateway provides a Software Bill of Materials (SBOM) for each container image to support supply chain transparency. The SBOM is available in CycloneDX format (v1.7). It is generated at build time and contains the complete dependency tree of the image, including licenses and versions.
Third-party components are identified using the package URL (purl) format. License information is listed as SPDX license expressions using identifiers from the SPDX license list.
Retrieving an SBOM
Airlock Microgateway SBOMs are cryptographically signed and attached to container images as attestations, making them both retrievable and verifiable. You can retrieve a container image attestation using Cosign, which supports software artifact signing, verification, and storage in an OCI (Open Container Initiative) registry.
Prerequisites
To retrieve an attestation with Cosign, install the following tools on your local machine:
cosignjq
Retrieve a container image attestation with Cosign
Use the cosign download attestation command to retrieve attestations for Airlock Microgateway container images. Different attestation types are referenced by their predicate type.
The following example downloads the CycloneDX attestation for the Airlock Microgateway Operator image:
Cosign returns the attestation in a signed envelope, with the SBOM stored as a base64-encoded payload. The command pipes the output to jq, which extracts the payload, decodes it, and prints the attestation predicate containing the SBOM.
Verify a container image attestation with Cosign
Use the cosign verify-attestation command to verify the attestation and the authenticity of the software producer.
The following example verifies the CycloneDX attestation for the Airlock Microgateway Operator image:
License Texts
Airlock Microgateway-related license information is included in the container images.
License extraction from a container image
License files are part of the images, such as the Airlock Microgateway Operator image. They can be extracted from the /licenses folder of temporarily created docker containers.
Example:
License-related content in container images
See the following table for a list of license-related image content.
| Image | Path | Content |
|---|---|---|
|
/licenses |
|