Skip to main content

CBOM Output

Kestrel generates CycloneDX 1.6 CBOMs that describe cryptographic algorithm usage.

kestrel scan --cbom --output cbom.json

You can also audit existing CBOMs:

kestrel cbom-audit --input cbom.json --frameworks fips_140_3,pci_dss_4