Is it possible to store dependency graph in J1?
JSONJ
mod
Similar to this https://npmgraph.js.org/?q=dat
? And query it with the API?
0
Best Answer
-
Yes, we have an open source util that generates SBOM file, and a util that ingest them into the graph to allow querying and visualization.
Docker image for generating an SBOM:
https://github.com/JupiterOne/node-cdx-bom
Pull that into J1 to build the graph in the CI/CD pipeline:
https://github.com/JupiterOne/j1-cicd-catalog
We also have this example:
https://github.com/JupiterOne/secops-automation-examples/tree/main/npm-inventory
0
This Month's Leaders
Categories
- 336 All Categories
- Featured Categories
- 7 About the AskJ1 Community
- 11 Product Announcements
- From Mission Control
- 1 Rapid Response
- 3 How J1 Uses J1
- Topics
- 131 Asset Management
- 56 Compliance & Reporting
- 65 Security Operations
- 40 Security Engineering
- 5 Open Source
- 18 News, Careers and More