ECZ-ID SBOM Readiness
Review your software bill-of-materials evidence before you share it.
Free, local-first. No source upload. No sign-in to run a check.
- Surfaces CycloneDX SBOM (bom.json / .cdx) and related evidence — locally, by filename and path.
- Builds a local, claim-free evidence summary you can review and share.
- Routes to Resolver lookup, implementation guidance and supported setup.
Useful for
Useful across many legitimate roles. Commonly used by:
- Software and platform teams
- Software-supply-chain owners
- Security engineers
- Customers and auditors requesting an SBOM
Relevant when before you share a release SBOM, you are confirming SBOM / lockfile / VEX presence, an auditor requests bill-of-materials evidence.
What you can do in under a minute
- Open or scan the workspace — run
ECZ-ID SBOM Readiness: Review / Scan Workspace.
- Review the evidence — observed and not-observed, in plain English.
- Open implementation guidance or continue supported setup where relevant.
What it looks for
- CycloneDX SBOM (bom.json / .cdx)
- SPDX documents
- Dependency lockfiles
- VEX / CSAF documents
Example use cases
- Before sharing a release SBOM with a customer or auditor.
- Confirming a repo has CycloneDX/SPDX, a lockfile and VEX evidence.
Example result
ECZ-ID SBOM Readiness - supply-chain evidence
- bom.json (CycloneDX) ... present
- package-lock.json ...... present
- VEX / CSAF ............. not observed, review recommended
Example result — when evidence and proof are present
ECZ-ID SBOM Readiness - complete evidence
- bom.json (CycloneDX) ... present
- spdx.json (SPDX) ....... present
- VEX / CSAF ............. present
Posture: resolvable - re-check before reliance
What results mean
Results describe observed evidence and public-proof posture — never a safety, approval, certification or compliance verdict:
evidence observed · evidence not observed · review required · no public proof reference found yet · re-check before reliance · your local policy decides.
There is no “pass/fail”. Local policy decides what is sufficient, and you should re-check before reliance.
Recommended next steps
- Show evidence — observed and not-observed, no verdict.
- Build evidence summary — a local, claim-free document you can review and save explicitly.
- Open implementation guidance — Developer Gateway.
- Open Resolver — read-only public proof lookup.
- Request Resolver Proof — for a third-party target (claim-free request).
- Begin supported setup — hand off to TrustOps (metadata only).
- Re-check later — re-run before you rely on a result.
Privacy & permissions
| Question |
Answer |
| Files read |
Filenames and paths during a normal scan |
| File contents read |
No — detection is filename/path only |
| Anything uploaded |
No source, prompts, secrets or tool payloads leave your device |
| Network destinations |
Only links you click, and an optional user-initiated public interface refresh |
| Telemetry |
None |
| Retention |
None |
| Workspace Trust |
Respected; scanning is gated by VS Code Workspace Trust |
See the bundled PRIVACY.md for the full notice.
Frequently asked questions
Is this extension free?
Yes. Every local check is free — you never need to sign in or pay to run one.
Does it upload my source code?
No. Detection is filename/path only; no source, prompts, secrets or tool payloads ever leave your device, and there is no telemetry.
Does a missing item mean something is wrong?
No. “Evidence not observed” is neutral — your local policy decides what is sufficient.
What does it do when the public interface service is unavailable?
It keeps working from a bundled fallback contract. A refresh is optional and user-initiated.
What it does not do
- No source / prompt / secret upload, and no telemetry.
- Provides local evidence review and guidance only - it does not issue ECZ-ID proof, activate services, grant access, or make approval, safety, insurance or compliance decisions.
- Makes no safety, approval, certification or compliance claim.
- Runs no checkout or payment — commercial actions happen only in TrustOps.
Install & first use
- In your editor's Extensions view, search for ECZ-ID SBOM Readiness (publisher EcoCitizenz) and install it.
- Open a project and trust the workspace.
- Run
ECZ-ID SBOM Readiness: Review / Scan Workspace and review the evidence.
Free vs supported setup
- Free, local-first: observed / not-observed SBOM evidence, an evidence summary you can save, and routes — no sign-in and no purchase to run a check.
- Supported setup (TrustOps): maintained ECZ-ID identity, public proof and lifecycle for shareable SBOM evidence — relevant when you need a resolver-verifiable result others can check, not just local review.
- You never need to buy anything to get local value; supported setup is a separate, optional step handled entirely in TrustOps.
Python / CLI
Prefer Python, CI or terminal automation?
python -m pip install ecz-id-sbom
ecz-id-sbom --help
The Python tools run locally and inspect, explain and route only — the same role boundary as this extension. They do not issue an ECZ-ID, create public proof or replace Resolver proof.
Machine-readable facts
| Field |
Value |
| Product |
ECZ-ID SBOM Readiness |
| Identity |
ecocitizenz.eczid-sbom-readiness |
| Publisher |
EcoCitizenz |
| License |
Free; see the bundled LICENSE.txt |
| Version |
0.1.3 |
| Page family |
functional-extension |
| Purpose |
Review your software bill-of-materials evidence before you share it. |
| Applicable audiences |
Software and platform teams; Software-supply-chain owners; Security engineers; Customers and auditors requesting an SBOM |
| Applicable scenarios |
before you share a release SBOM; you are confirming SBOM / lockfile / VEX presence; an auditor requests bill-of-materials evidence |
| Primary command |
ECZ-ID SBOM Readiness: Review / Scan Workspace |
| Inputs |
CycloneDX SBOM (bom.json / .cdx), SPDX documents, dependency lockfiles, VEX / CSAF documents |
| Outputs |
Observed / not-observed SBOM evidence, an evidence summary you can save, and routes |
| Data handling |
Filenames and paths only; no source / prompt / secret upload; no telemetry; retention none |
| Network behaviour |
Only links you open, plus an optional user-initiated public-interface refresh (GET, allowlisted ECZ-ID host) |
| Result states |
evidence observed; evidence not observed; no public proof reference found yet; review recommended; re-check before reliance; local policy decides |
| Limitations |
Does not issue proof, approve, certify, insure, underwrite, determine compliance, or run checkout |
| Canonical machine discovery |
https://machine.ecocitizenz.org/.well-known/ecz-machine.json |
| Public proof |
https://resolver.ecocitizenz.org |
| Documentation |
https://developers.ecocitizenz.com |
| Supported setup |
https://trustops.ecocitizenz.com/start |
| Re-check |
Re-run before reliance |
Need help choosing the right ECZ-ID route?
Use ECZ-ID GPT guidance: https://trustops.ecocitizenz.com/start#gpt-guidance
Route guidance only. TrustOps handles setup; Backend/Core writes truth; Resolver proves public state. Local policy decides reliance. Re-check before reliance.
Links & support
ECZ-ID is independent trust infrastructure. Third-party names describe compatible ecosystems only and do not imply endorsement or affiliation. Local policy decides whether the evidence you review is sufficient.