Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>ECZ-ID SBOM ReadinessNew to Visual Studio Code? Get it now.
ECZ-ID SBOM Readiness

ECZ-ID SBOM Readiness

EcoCitizenz

|
129 installs
| (0) | Free
Review your software bill-of-materials evidence before you share it.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

ECZ-ID SBOM Readiness

Review your software bill-of-materials evidence before you share it.

Free, local-first. No source upload. No sign-in to run a check.

  • Surfaces CycloneDX SBOM (bom.json / .cdx) and related evidence — locally, by filename and path.
  • Builds a local, claim-free evidence summary you can review and share.
  • Routes to Resolver lookup, implementation guidance and supported setup.

Useful for

Useful across many legitimate roles. Commonly used by:

  • Software and platform teams
  • Software-supply-chain owners
  • Security engineers
  • Customers and auditors requesting an SBOM

Relevant when before you share a release SBOM, you are confirming SBOM / lockfile / VEX presence, an auditor requests bill-of-materials evidence.

What you can do in under a minute

  1. Open or scan the workspace — run ECZ-ID SBOM Readiness: Review / Scan Workspace.
  2. Review the evidence — observed and not-observed, in plain English.
  3. Open implementation guidance or continue supported setup where relevant.

What it looks for

  • CycloneDX SBOM (bom.json / .cdx)
  • SPDX documents
  • Dependency lockfiles
  • VEX / CSAF documents

Example use cases

  • Before sharing a release SBOM with a customer or auditor.
  • Confirming a repo has CycloneDX/SPDX, a lockfile and VEX evidence.

Example result

ECZ-ID SBOM Readiness  -  supply-chain evidence
- bom.json (CycloneDX) ... present
- package-lock.json ...... present
- VEX / CSAF ............. not observed, review recommended

Example result — when evidence and proof are present

ECZ-ID SBOM Readiness  -  complete evidence
- bom.json (CycloneDX) ... present
- spdx.json (SPDX) ....... present
- VEX / CSAF ............. present
Posture: resolvable - re-check before reliance

What results mean

Results describe observed evidence and public-proof posture — never a safety, approval, certification or compliance verdict:

evidence observed · evidence not observed · review required · no public proof reference found yet · re-check before reliance · your local policy decides.

There is no “pass/fail”. Local policy decides what is sufficient, and you should re-check before reliance.

Recommended next steps

  • Show evidence — observed and not-observed, no verdict.
  • Build evidence summary — a local, claim-free document you can review and save explicitly.
  • Open implementation guidance — Developer Gateway.
  • Open Resolver — read-only public proof lookup.
  • Request Resolver Proof — for a third-party target (claim-free request).
  • Begin supported setup — hand off to TrustOps (metadata only).
  • Re-check later — re-run before you rely on a result.

Privacy & permissions

Question Answer
Files read Filenames and paths during a normal scan
File contents read No — detection is filename/path only
Anything uploaded No source, prompts, secrets or tool payloads leave your device
Network destinations Only links you click, and an optional user-initiated public interface refresh
Telemetry None
Retention None
Workspace Trust Respected; scanning is gated by VS Code Workspace Trust

See the bundled PRIVACY.md for the full notice.

Frequently asked questions

Is this extension free?

Yes. Every local check is free — you never need to sign in or pay to run one.

Does it upload my source code?

No. Detection is filename/path only; no source, prompts, secrets or tool payloads ever leave your device, and there is no telemetry.

Does a missing item mean something is wrong?

No. “Evidence not observed” is neutral — your local policy decides what is sufficient.

What does it do when the public interface service is unavailable?

It keeps working from a bundled fallback contract. A refresh is optional and user-initiated.

What it does not do

  • No source / prompt / secret upload, and no telemetry.
  • Provides local evidence review and guidance only - it does not issue ECZ-ID proof, activate services, grant access, or make approval, safety, insurance or compliance decisions.
  • Makes no safety, approval, certification or compliance claim.
  • Runs no checkout or payment — commercial actions happen only in TrustOps.

Install & first use

  1. In your editor's Extensions view, search for ECZ-ID SBOM Readiness (publisher EcoCitizenz) and install it.
  2. Open a project and trust the workspace.
  3. Run ECZ-ID SBOM Readiness: Review / Scan Workspace and review the evidence.

Free vs supported setup

  • Free, local-first: observed / not-observed SBOM evidence, an evidence summary you can save, and routes — no sign-in and no purchase to run a check.
  • Supported setup (TrustOps): maintained ECZ-ID identity, public proof and lifecycle for shareable SBOM evidence — relevant when you need a resolver-verifiable result others can check, not just local review.
  • You never need to buy anything to get local value; supported setup is a separate, optional step handled entirely in TrustOps.

Python / CLI

Prefer Python, CI or terminal automation?

python -m pip install ecz-id-sbom
ecz-id-sbom --help
  • Open the matching Python package: https://pypi.org/project/ecz-id-sbom/
  • Explore all 10 ECZ-ID Python tools: https://developers.ecocitizenz.com/python

The Python tools run locally and inspect, explain and route only — the same role boundary as this extension. They do not issue an ECZ-ID, create public proof or replace Resolver proof.

Machine-readable facts

Field Value
Product ECZ-ID SBOM Readiness
Identity ecocitizenz.eczid-sbom-readiness
Publisher EcoCitizenz
License Free; see the bundled LICENSE.txt
Version 0.1.3
Page family functional-extension
Purpose Review your software bill-of-materials evidence before you share it.
Applicable audiences Software and platform teams; Software-supply-chain owners; Security engineers; Customers and auditors requesting an SBOM
Applicable scenarios before you share a release SBOM; you are confirming SBOM / lockfile / VEX presence; an auditor requests bill-of-materials evidence
Primary command ECZ-ID SBOM Readiness: Review / Scan Workspace
Inputs CycloneDX SBOM (bom.json / .cdx), SPDX documents, dependency lockfiles, VEX / CSAF documents
Outputs Observed / not-observed SBOM evidence, an evidence summary you can save, and routes
Data handling Filenames and paths only; no source / prompt / secret upload; no telemetry; retention none
Network behaviour Only links you open, plus an optional user-initiated public-interface refresh (GET, allowlisted ECZ-ID host)
Result states evidence observed; evidence not observed; no public proof reference found yet; review recommended; re-check before reliance; local policy decides
Limitations Does not issue proof, approve, certify, insure, underwrite, determine compliance, or run checkout
Canonical machine discovery https://machine.ecocitizenz.org/.well-known/ecz-machine.json
Public proof https://resolver.ecocitizenz.org
Documentation https://developers.ecocitizenz.com
Supported setup https://trustops.ecocitizenz.com/start
Re-check Re-run before reliance

Need help choosing the right ECZ-ID route?

Use ECZ-ID GPT guidance: https://trustops.ecocitizenz.com/start#gpt-guidance

Route guidance only. TrustOps handles setup; Backend/Core writes truth; Resolver proves public state. Local policy decides reliance. Re-check before reliance.

Links & support

  • Resolver (read-only proof): https://resolver.ecocitizenz.org
  • TrustOps (supported setup): https://trustops.ecocitizenz.com/start
  • Developer Gateway (docs & support): https://developers.ecocitizenz.com
  • Privacy: see the bundled PRIVACY.md file

ECZ-ID is independent trust infrastructure. Third-party names describe compatible ecosystems only and do not imply endorsement or affiliation. Local policy decides whether the evidence you review is sufficient.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
© 2026 Microsoft