Retention strategy
How many versions of an SBOM to keep active, so vulnerabilities and violations count only what is deployed.
A pipeline that uploads an SBOM on every build adds a new version of the same application each time. If they all stay active, the component list, vulnerabilities, and policy violations count every old build as if it were still running. Retention archives the older versions so the active set matches what is deployed.
How many versions to keep depends on what the history is for:
- Keep 1 for builds where only the current state matters, such as feature branches or internal tools.
- Keep more for a service that runs several versions at once, or where an investigation may need to see what an earlier release contained.
- Keep dependencies (on by default in the CLI) when other components depend on a specific version, so that version stays active while something still uses it.
Archived versions stay available under the Archived tab, so lowering the keep count doesn't lose evidence.
Related
- Reference: Retention policies