Collect and monitor vendor SBOMs

Collect SBOMs and VEX from suppliers with Trust Repository, import them into SBOM Observer, and keep track of the vulnerabilities in their software.

Software you buy contains components you didn't choose. Once a supplier's SBOM is in SBOM Observer, those components get the same vulnerability matching, impact analysis, and policies as your own.

Getting the SBOMs is the hard part. Trust Repository is the Bytesafe product for collecting them from suppliers. SBOM Observer is where you analyze them.

Collect from suppliers with Trust Repository

Asking each supplier for files by email works once. After that, every supplier sends different documents in its own format and on its own schedule, and later nobody can say which SBOM covered which release.

In Trust Repository, each supplier gets its own space to publish into:

  • You invite a supplier by email or with a short code. The supplier sees only its own products and releases, needs no access to your systems, and can't see your other suppliers.
  • The supplier publishes SBOMs, VEX statements, and end-of-life dates per release, from its CI/CD pipeline over the REST API or by uploading in the browser.
  • A supplier with nothing machine-readable can still be on record. You add it yourself and upload a PDF assessment, then replace it with an SBOM later without losing the history.

Each document is versioned and kept with the release it covers, and every download is recorded. The same Trust Repository publishes your own SBOMs and VEX to your customers and partners; see Share SBOMs with customers.

Import into SBOM Observer

Get the SBOM and VEX

For each supplier product and version you run, take the CycloneDX or SPDX SBOM and any VEX documents from Trust Repository. A supplier outside Trust Repository can send the same files directly.

Upload them

On the Attestations page, select Upload and add the files. From a script or pipeline, use the CLI:

observer upload vendor-product-1.2.3.cdx.json

Upload VEX documents the same way; their analysis attaches to the matching vulnerabilities.

Check what arrived

The SBOM's top-level component appears under Applications, and its components under Components. Suppliers named in the SBOM appear under Suppliers; mappings merge different spellings of one supplier.

Watch for new vulnerabilities

Supplier components are rescanned in the background along with your own, so a vulnerability disclosed after upload still shows up under Vulnerabilities. When one does, analyze its impact to see which supplier products and internal systems include it.

Policies apply to supplier software too. A component-scoped policy flags vulnerable supplier components, and a supplier-scoped policy checks the supplier record itself, for example that a contact is registered. See Write and test policies.

Next steps