SBOM Observer
Documentation for SBOM Observer: import SBOMs, find vulnerabilities, and enforce policies.
SBOM Observer imports SBOMs from your builds and your suppliers, finds the vulnerabilities in the components they list, and flags components that break your policies.
Start here
What is SBOM Observer?
What SBOM Observer does, from importing SBOMs to vulnerabilities, policies, and sharing.
Quickstart
Upload an SBOM, create a policy, and see its violations in the live demo. No signup.
Using the CLI
Install the Observer CLI, generate an SBOM, analyze it, and upload it.
CI/CD integration
Generate, verify, analyze, and upload an SBOM in a GitHub Actions workflow, failing the build on fail-build violations.
Common tasks
Generate and upload SBOMs
Generate an SBOM with Observer CLI or another tool, and upload it in the web interface, with the CLI, or through the API.
Enforce policies in CI/CD
Fail a CI/CD build when an SBOM breaks a policy, with a fail-build action and observer analyze --fail.
Analyze vulnerability impact
Find every application, container, and project a vulnerability reaches, and record VEX analysis.
Write and test policies
Write policies in the Visual Builder, Rego, or JavaScript, and test them before saving.
Look things up
Observer CLI
Observer CLI commands, flags, and environment variables.
Data model
Namespaces, attestations, the index, annotations, and mappings, and how they relate.
Formats and standards
SBOM formats, attestation types, and standards SBOM Observer accepts.
Roles and permissions
Organization roles in SBOM Observer and the permissions each one grants.