Installation¶
Installation is fairly simple. We provide ts-obom as a PIP package. You will require a recent Python version (v3.10, v3.11 and v3.12 are tested) and pip (v22+).
Installation from the PyPI repository¶
Everything the scanner needs is a regular dependency of the package. There is no optional extra and no separate Checkov installation.
Installation from a local folder¶
Alternatively you may clone the repository and install it directly into your environment:
For development install the dev extra as well, which adds pytest and pyright:
Docker image¶
Every release is published as trustsource/ts-obom on Docker Hub, tagged with the release version and latest:
See Operating inside a container for how to mount your sources.