Because with Nix you define your whole system as a Nix expression, it should be possible to get an inventory of everything for further analysis - for example for vulnerability scanning.

Of course it's never quite that easy! There's a lot of potential, but also a lot of work remaining before we can get a nice signal-to-noise ratio without missing things.

I wrote up an introduction to and summary of the current state of SBOM tools for NixOS, including nice clickable example output. Still a bit of a draft, I expect updates - feedback welcome!

arnout.engelen.eu/blog/nix-sta

one of the browsable SBOMs: a tree of the run-time dependencies of 'nethogs' and the start of the 'raw' SBOM itself.
0

If you have a fediverse account, you can quote this note from your own instance. Search https://merveilles.town/users/raboof/statuses/115775130193879755 on your instance and quote it. (Note that quoting is not supported in Mastodon.)