Skip to content
| Marketplace
Sign in
Visual Studio Code>Testing>SBOM ToolNew to Visual Studio Code? Get it now.
SBOM Tool

SBOM Tool

masahiroid

|
1 install
| (0) | Free
Generate SBOM and run vulnerability checks for the current workspace
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

SBOM Tool

  • English: README.md
  • 日本語: README.ja.md

SBOM Tool generates SBOM files and runs vulnerability checks for the currently opened workspace.

Download VSIX

Use this file for installation:

  • releases/sbom-tool-latest.vsix

You can also use a version-pinned file in releases. Current version example: releases/sbom-tool-0.1.1.vsix

Install from Marketplace (recommended)

Once published to VS Code Marketplace, install SBOM Tool from the Extensions view. Marketplace installations support automatic updates.

Dashboard (Activity Bar)

After installation, an SBOM Tool icon appears in the Activity Bar. From the Dashboard you can:

  • Check the currently opened project
  • Switch vulnerability scanner (auto / trivy / npm-audit)
  • Switch UI language (auto / en / ja)
  • Switch result open mode (vscode / external)
  • Run SBOM generation and vulnerability scan actions

Commands

  • SBOM Tool: Generate SBOM
  • SBOM Tool: Scan Vulnerabilities
  • SBOM Tool: Generate SBOM + Scan Vulnerabilities
  • SBOM Tool: Check Current Project
  • SBOM Tool: Select Scanner
  • SBOM Tool: Select UI Language
  • SBOM Tool: Select Result Open Mode

Output

By default, output files are generated under .sbom-tool/ in your workspace.

  • sbom-raw-*.json: Internal parsed SBOM data
  • sbom-cyclonedx-*.json or sbom-spdx-*.spdx: Exported SBOM
  • vulnerability-report-*.json: Vulnerability scan result

Settings

  • sbomTool.outputDirectory (default: .sbom-tool)
  • sbomTool.defaultSbomFormat (default: cyclonedx-json)
    • cyclonedx-json
    • spdx
  • sbomTool.vulnerabilityScanner (default: auto)
    • auto: Tries Trivy first, falls back to npm audit
    • trivy: Uses Trivy only
    • npm-audit: Uses npm audit only
  • sbomTool.uiLanguage (default: auto)
    • auto: Follows VS Code display language
    • en: English
    • ja: Japanese
  • sbomTool.resultOpenMode (default: vscode)
    • vscode: Opens reports inside VS Code
    • external: Opens reports in external browser

Prerequisites

  • Node.js / npm
  • Trivy installed (when using trivy mode)

Language Support

  • Default language: English
  • Supported language: Japanese (when VS Code display language is ja)

Package

cd vscode-extension/csap-sbom-security
npm install
npm run release:patch

Publish (Marketplace)

cd vscode-extension/csap-sbom-security
npm install
npm run publish:patch

See PUBLISHING.md for complete setup (publisher and PAT).

License

Apache License 2.0

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft