Policies
What a policy is, when SBOM Observer evaluates it, and what its scope decides.
A policy is a rule that turns SBOM data into a list of things that need action. A namespace can hold thousands of vulnerabilities; a policy such as "no libraries with severity above 7 and EPSS above 0.5, unless VEX says not affected" narrows that to the components that break the rule. Each match is a policy violation.
How policies are evaluated
SBOM Observer evaluates every enabled policy in a namespace against the current data, and does it again whenever that data changes: an SBOM is uploaded or archived, a component or VEX analysis is edited, a policy is created or changed, or a background rescan picks up new vulnerability data. The violation list therefore includes vulnerabilities disclosed after an SBOM was uploaded.
Scopes
A policy's scope decides what it runs against and what input it receives:
| Scope | Runs once per | Typical rule |
|---|---|---|
| Component | component, with its vulnerabilities | no critical vulnerabilities in libraries, only approved licenses |
| Attestation | uploaded attestation (SBOM, VEX, ...) | SBOMs must include supplier and timestamp |
| Supplier | supplier | suppliers must have a contact or an identifier |
The exact input for each scope is in the policy inputs reference.
Visual Builder, Rego, or JavaScript
A policy is built in the Visual Builder (conditions picked from lists, no code) or written as Rego or JavaScript. Code policies suit logic the builder can't express and can be kept in version control. Only code policies can set a violation's action, such as fail-build.
One-way conversion
A Visual Builder policy can be converted to Rego. The conversion can't be undone; save a copy first if you want to keep the builder version.
Policies in CI/CD
The CLI can evaluate an SBOM against a namespace's policies before upload and fail the build when a violation's action is fail-build. See Enforce policies in CI/CD.
Related
- Getting started: First policy
- How-to: Write and test policies
- Reference: Component-scoped input
- Concept: Data model fundamentals