Platform

Software Bill of Materials

What is it?

The Software Bill of Materials (SBOM) is an inventory of "third party" components used in building Synadia Platform. The SBOM provides transparency into software dependencies, including versions and licensing, and allows for easier compliance and vulnerability identification.

Each platform component publishes its SBOM in the SPDX format as a release asset in the linked repository. Each component below includes a dependency summary. Choose a version to see its inventory; the latest stable release is selected by default.

NATS includes all patch releases in its three most recent minor series. The oldest series is marked Unsupported and is included for existing deployments. Other components include releases published in the last six months, plus their latest stable release.

The tooling used to generate the SBOMs is sometimes over-inclusive, including dependencies only used for testing. The summaries here are generated via Go-aware tooling which includes fewer extra matches.

NATS

nats-io/nats-server

Loading SBOM…

Control Plane

synadia-io/control-plane

Loading SBOM…

synadia-io/private-link

Loading SBOM…

HTTP Gateway

synadia-io/http-gateway

Loading SBOM…

Workloads

synadia-io/nex-ce

Loading SBOM…

Connectors

synadia-io/connect-node

Loading SBOM…

synadia-io/connect-runtime-wombat

Loading SBOM…

Schema Registry

synadia-io/schema-registry

Loading SBOM…

Signed Attestation

Currently, only the control-plane OCI images are signed. This is being rolled out for the rest of the components.

For components distributed as OCI images, attestations are signed by a Synadia key to allow for verification of authenticity. This can be validated using Sigstore Cosign.

Signature Verification:

cosign verify-attestation \
    --certificate-identity-regexp '^https://github.com/ConnectEverything' \
    --certificate-oidc-issuer https://token.actions.githubusercontent.com \
    registry.synadia.io/<component> > /dev/null

Replace <component> with the component name (e.g., control-plane, http-gateway).

In the above command, we redirected STDOUT to /dev/null because it contains the complete SBOM as base64-encoded JSON. We are able to decode this if we want to see the SBOM itself.

cosign verify-attestation \
    --certificate-identity-regexp '^https://github.com/ConnectEverything' \
    --certificate-oidc-issuer https://token.actions.githubusercontent.com \
    registry.synadia.io/<component> \
    | jq -r '.payload' | base64 -d | jq '.predicate.Data | fromjson'