Policies

What a policy is, when SBOM Observer evaluates it, and what its scope decides.

A policy is a rule that turns SBOM data into a list of things that need action. A namespace can hold thousands of vulnerabilities; a policy such as "no libraries with severity above 7 and EPSS above 0.5, unless VEX says not affected" narrows that to the components that break the rule. Each match is a policy violation.

How policies are evaluated

SBOM Observer evaluates every enabled policy in a namespace against the current data, and does it again whenever that data changes: an SBOM is uploaded or archived, a component or VEX analysis is edited, a policy is created or changed, or a background rescan picks up new vulnerability data. The violation list therefore includes vulnerabilities disclosed after an SBOM was uploaded.

Define policyonce
Triggernew SBOM, changed component, new vulnerability data
Evaluate every component
Rule applies?
Violation recordedlisted under Policy Violations
Compliant

Scopes

A policy's scope decides what it runs against and what input it receives:

ScopeRuns once perTypical rule
Componentcomponent, with its vulnerabilitiesno critical vulnerabilities in libraries, only approved licenses
Attestationuploaded attestation (SBOM, VEX, ...)SBOMs must include supplier and timestamp
Suppliersuppliersuppliers must have a contact or an identifier

The exact input for each scope is in the policy inputs reference.

Visual Builder, Rego, or JavaScript

A policy is built in the Visual Builder (conditions picked from lists, no code) or written as Rego or JavaScript. Code policies suit logic the builder can't express and can be kept in version control. Only code policies can set a violation's action, such as fail-build.

One-way conversion

A Visual Builder policy can be converted to Rego. The conversion can't be undone; save a copy first if you want to keep the builder version.

Policies in CI/CD

The CLI can evaluate an SBOM against a namespace's policies before upload and fail the build when a violation's action is fail-build. See Enforce policies in CI/CD.