All how-to guides
Task guides for common workflows in SBOM Observer.
Step-by-step guides for one task each, such as uploading SBOMs, failing a build on a policy, or tracing a vulnerability. See concepts for how SBOM Observer works.
Analyze vulnerability impact
Find every application, container, and project a vulnerability reaches, and record VEX analysis.
Collect and monitor vendor SBOMs
Collect SBOMs and VEX from suppliers with Trust Repository, import them into SBOM Observer, and keep track of the vulnerabilities in their software.
Compare two SBOMs
See which components, vulnerabilities, and policy violations changed between two SBOMs, for example two releases of one application.
Enforce policies in CI/CD
Fail a CI/CD build when an SBOM breaks a policy, with a fail-build action and observer analyze --fail.
Evaluate open source components
Check the open source project behind a component on the OSS Insights tab, with repository activity, the OpenSSF Scorecard, and SLSA provenance.
Generate and upload SBOMs
Generate an SBOM with Observer CLI or another tool, and upload it in the web interface, with the CLI, or through the API.
Generate SBOMs at build time
Trace a build with eBPF to create an SBOM that includes the OS packages and toolchain the build used.
Generate SBOMs for containers and Kubernetes
Create SBOMs for container images and Kubernetes clusters with Observer CLI, and review an image layer by layer.
Manage projects
Create a project, add components to it, and analyze impact for the whole system.
Share SBOMs with customers
Export an SBOM from SBOM Observer, and publish SBOMs and VEX to customers with Trust Repository.
Write and test policies
Write policies in the Visual Builder, Rego, or JavaScript, and test them before saving.