SBOM ingestion

Supported formats: CycloneDX 1.2–1.6 (JSON, XML) and SPDX 2.2–2.3 (JSON, tag-value), up to 25 MB. Documents are stored immutably with a SHA-256 checksum; only one SBOM is *latest* per version.

Sources

  • Upload from the product or version page
  • GitHub App: dependency-graph SBOM export per linked repository, releases become versions, Dependabot alerts and repository advisories are recorded as findings
  • GitLab: group/project access token, CycloneDX artefacts from the latest successful pipeline, releases become versions
  • CI/CD: push from GitHub Actions, GitLab CI, Jenkins or CircleCI with the API (see CI/CD)

Processing

Parsing runs in the background: components are deduplicated by package URL, licenses are classified (permissive / weak / strong / network copyleft, unknown, conflicts), dependency depth is computed, then every component is matched against vulnerability intelligence and priorities are recalculated. Hard limits protect the parser (250k components, 1M edges, nesting depth 32).

Comparing versions

Compare SBOMs on any version shows components added, removed, upgraded, downgraded, new and resolved vulnerabilities and license changes between two releases — the release-security view.

Last updated . This page describes the current release.