Projects
What projects are in SBOM Observer, how they differ from applications, and how they follow new versions.
A project is a group of components you define yourself, to treat them as one system. A platform made of several services, a set of containers deployed together, or the libraries one team owns can each be a project.
Projects and applications
Both are components with dependencies. The difference is where they come from: an application is imported from an SBOM, a project is created in SBOM Observer and its components are picked by hand. A project can include a component at any level, not only the top-level component of an SBOM, so a single shared library can be a member alongside whole applications.
Projects follow new versions
When an SBOM is uploaded for a component that is already in a project (same name, group, and type), the project switches to the new version. A project for "Customer Portal" therefore keeps pointing at the latest uploaded version of each of its services without being edited after each release. To keep a component at its current version, turn off Auto Update for it on the project's Components tab.
When to create a project
Impact analysis on a project shows which of its components a vulnerability reaches, including through containers and transitive libraries. That answers "is this system affected?" for systems that span several SBOMs, which a single application can't.
Create a project when a system spans more than one SBOM, or when you want to follow a group of components by team or business domain rather than by the SBOM they came from.
Related
- How-to: Manage projects
- Getting started: Impact analysis