Getting started
Try SBOM Observer, install the CLI, and run it in CI/CD.
Start here if you are new to SBOM Observer. These pages explain what it does, walk through the live demo, then set up the CLI, an access token, and a CI/CD pipeline.
What is SBOM Observer?
What SBOM Observer does, from importing SBOMs to vulnerabilities, policies, and sharing.
Quickstart
Upload an SBOM, create a policy, and see its violations in the live demo. No signup.
Using the CLI
Install the Observer CLI, generate an SBOM, analyze it, and upload it.
CI/CD integration
Generate, verify, analyze, and upload an SBOM in a GitHub Actions workflow, failing the build on fail-build violations.
First policy
Build a Visual Builder policy that flags high-severity vulnerabilities and see its violations.
Access tokens
Create and revoke the personal access tokens the CLI and API use to reach a namespace.
Impact analysis
Trace a vulnerability to the containers and projects that include it, in the live demo.