Platform
Software Bill of Materials
What is it?
The Software Bill of Materials (SBOM) is an inventory of "third party" components used in building Synadia Platform. The SBOM provides transparency into software dependencies, including versions and licensing, and allows for easier compliance and vulnerability identification.
Each platform component publishes its SBOM in the SPDX format as a release asset in the linked repository. Each component below includes a dependency summary. Choose a version to see its inventory; the latest stable release is selected by default.
NATS includes all patch releases in its three most recent minor series. The oldest series is marked Unsupported and is included for existing deployments. Other components include releases published in the last six months, plus their latest stable release.
The tooling used to generate the SBOMs is sometimes over-inclusive, including dependencies only used for testing. The summaries here are generated via Go-aware tooling which includes fewer extra matches.
NATS
Loading SBOM…
Control Plane
Loading SBOM…
Private Link
Loading SBOM…
HTTP Gateway
Loading SBOM…
Workloads
Loading SBOM…
Connectors
Loading SBOM…
Loading SBOM…
Schema Registry
Loading SBOM…
Signed Attestation
Currently, only the control-plane OCI images are signed. This is being rolled out for the rest of the components.
For components distributed as OCI images, attestations are signed by a Synadia key to allow for verification of authenticity. This can be validated using Sigstore Cosign.
Signature Verification:
cosign verify-attestation \
--certificate-identity-regexp '^https://github.com/ConnectEverything' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
registry.synadia.io/<component> > /dev/null
Replace <component> with the component name (e.g., control-plane, http-gateway).
In the above command, we redirected STDOUT to /dev/null because it contains the complete SBOM as base64-encoded JSON. We are able to decode this if we want to see the SBOM itself.
cosign verify-attestation \
--certificate-identity-regexp '^https://github.com/ConnectEverything' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
registry.synadia.io/<component> \
| jq -r '.payload' | base64 -d | jq '.predicate.Data | fromjson'