You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JFrog X-ray SBOM导出API返回二进制内容问题求助及替代方案咨询

问题解决方案及替代导出方法

一、解决curl导出二进制文件问题

出现二进制文件的核心原因是X-Ray返回了gzip压缩的响应,但curl默认未自动解压,同时请求参数存在格式冲突,可按以下步骤修正:

1. 添加自动解压参数

在curl命令中加入--compressed,让curl自动处理gzip压缩的响应:

curl -u $USER_NAME:$API_KEY -X POST $ARTIFACT_DOMAIN_URL/xray/api/v1/component/exportDetails \
-H "Content-Type: application/json" \
-H "Accept: application/vnd.cyclonedx+json" \
--compressed \
-o "test.json" \
-d '{
    "component_name": "docker://test-docker-image:latest",
    "package_type": "docker",
    "sha_256": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
    "violations": true,
    "include_ignored_violations": false,
    "license": true,
    "exclude_unknown": false,
    "security": true,
    "malicious_code": false,
    "iac": false,
    "services": false,
    "applications": false,
    "cyclonedx": true,
    "cyclonedx_format": "json",
    "vex": false,
    "operational_risk": false
}'

2. 清理冲突参数

原请求中同时设置了output_format: "json"和cyclonedx: true,二者存在格式优先级冲突,建议移除output_format参数——启用CycloneDX格式后,该参数会被X-Ray自动忽略。

二、替代导出方法:使用JFrog CLI

相比curl,JFrog CLI专门针对JFrog生态优化,操作更简洁且不易出现格式问题:

1. 配置JFrog CLI

先完成环境配置(仅需执行一次):

jf c add --url $ARTIFACT_DOMAIN_URL --user $USER_NAME --apikey $API_KEY

2. 导出CycloneDX格式SBOM

执行以下命令导出指定镜像的SBOM:

jf xray export-component \
--component docker://test-docker-image:latest \
--sha256 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx \
--include-violations \
--include-licenses \
--include-security \
--output-format cyclonedx-json \
--output-file test.json

额外验证方法

如果仍不确定文件是否为有效JSON,可使用file命令检查文件类型:

file test.json

若返回test.json: JSON data或test.json: gzip compressed data,则说明文件本身有效,前者可直接读取,后者可通过gzip -d test.json解压后读取。

内容的提问来源于stack exchange,提问作者Arun Lal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 18:42:22