How to Export and Analyze Your BOM as CSV

Beginner 10 minutes Compliance Teams / Security Engineers Monitoring & Compliance

Export the full bill of materials with supply chain columns, filter before export, and use the CSV for compliance reporting.

Overview

While CycloneDX SBOMs are ideal for machine-to-machine integration, CSV exports are perfect for manual analysis in spreadsheets, sharing with non-technical stakeholders, and ad-hoc compliance reporting. Chainsaw’s CSV export includes 16 supply chain columns covering trust scores, provenance, malware detection, and more.

Prerequisites

  • Manager role or above in Chainsaw
  • Packages recorded in the Bill of Materials

Step 1: Navigate to the Bill of Materials

Click Bill of Materials in the sidebar.

Bill of Materials page
The BOM page is the starting point for CSV export

Step 2: Apply Filters

Filter the BOM to export only what you need:

  • Client Type: End User, Service Token, or AI Agent
  • Ecosystem: Filter to a specific package manager
  • Package Name: Search for specific packages
BOM filters applied
Filters applied before export carry through to the CSV
The CSV export respects all active filters. Filter first, then export to get a targeted report.

Step 3: Export as CSV

Click the Export as CSV button. The download begins immediately.

Export as CSV button
Click Export as CSV to download the filtered BOM

The file is named bom-YYYY-MM-DD.csv.

Step 4: Understand the CSV Columns

The exported CSV contains 16 fields:

ColumnDescription
formatPackage ecosystem (npm, pip, maven, etc.)
repositoryChainsaw repository name
package_namePackage name
package_versionPackage version
client_idClient credential that installed the package
client_typeEnd User, Service Token, or AI Agent
last_install_attemptTimestamp of the most recent install
install_countTotal number of installs for this package-client pair
last_outcomeSuccess, blocked, or flagged
provenance_statusVerified, unverified, unavailable, missing, or failed
malware_statusClean, malicious, or unknown
malware_idOSV identifier if malicious (e.g., MAL-2024-0001)
typosquat_statusClean, suspected, or confirmed_safe
typosquat_similar_toPopular package it’s similar to (if suspected)
checksum_verifiedWhether integrity hash was verified

Step 5: Analyze in a Spreadsheet

Open the CSV in your preferred spreadsheet tool. Useful analyses:

Filter for High-Risk Packages

Sort by malware_status and typosquat_status to surface the riskiest packages. The CSV no longer carries a composite trust score — see the intelligence API for the risk-v2 evaluation, which is scored per coordinate and kept current.

Spreadsheet sorted by trust score
Sort by trust score to surface high-risk packages

Identify Malware Hits

Filter malware_status for malicious to find any confirmed malware.

Provenance Coverage

Create a pivot table of provenance_status values to see what percentage of your supply chain has verified provenance.

Blocked Packages Report

Filter last_outcome for blocked to see all packages that were denied by policy.

Step 6: Export via API

For automated reporting, use the API:

curl -X GET "https://chain305.com/chainproxy/api/v1/bom/export?format=npm&client_type=service-token" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -o bom-$(date +%Y-%m-%d).csv

Available Query Parameters

ParameterDescriptionExample
formatFilter by ecosystemnpm, pip, maven
client_idFilter by client credentialabc123
client_typeFilter by client typeend-user, service-token, ai-agent
package_nameFilter by package namelodash
versionFilter by version (supports semver constraints)^4.0.0
Schedule a daily CSV export in your CI/CD pipeline and store it in your compliance artifact repository. This creates a historical record of your supply chain state over time.

Next Steps