All concepts
Mental models for how SBOM Observer works.
Background reading for how SBOM Observer works. No steps here, see how-to guides for tasks.
Attestations
What an SBOM, a VEX statement, and SLSA provenance each tell you about a release, and which ones to collect from your builds and your suppliers.
Authentication and access control
How users sign in to SBOM Observer, how sessions are managed, and how roles limit what a member can do.
Compliance mapping
How the software supply-chain requirements of the Cyber Resilience Act, NIS2, and DORA map to SBOMs, policies, and VEX in SBOM Observer.
Data model fundamentals
How SBOM Observer turns uploaded SBOMs, VEX, and provenance into one linked index that policies run against.
Deployment models
Cloud-hosted, self-hosted, and self-hosted air-gapped: what each needs and when to pick it.
Policies
What a policy is, when SBOM Observer evaluates it, and what its scope decides.
Projects
What projects are in SBOM Observer, how they differ from applications, and how they follow new versions.
Retention strategy
How many versions of an SBOM to keep active, so vulnerabilities and violations count only what is deployed.