Quickstart
Upload an SBOM, create a policy, and see its violations in the live demo. No signup.
Try SBOM Observer in the live demo, with no signup: optionally upload an SBOM, create a policy, and see the violations it finds.
every component in the workspace
Open the live demo
Go to the live demo and select Open Live Demo. You get a private namespace with sample SBOMs, not shared with other visitors. It resets after an hour of inactivity.
Upload an SBOM (optional)
Select Attestations, then Upload, and add a CycloneDX or SPDX SBOM.
To get one, generate it from a project with the Observer CLI, or download an example SBOM.
Skipping this step still lets you create policies against the existing demo data.
Create your first policy
Select Policies, then Add Policy, and build a rule in the Visual Builder. First policy walks through one example.
Review policy violations
Saving the policy evaluates it against every component. Open Policy Violations in the sidebar to see what it flagged.
Next steps
- Write and test policies in Rego or JavaScript, for rules the Visual Builder can't express.
- CI/CD integration to generate, check, and upload an SBOM on every build.
- Formats and standards for the SBOM formats and versions SBOM Observer accepts.