Compare two SBOMs
See which components, vulnerabilities, and policy violations changed between two SBOMs, for example two releases of one application.
Comparing two SBOMs shows what changed between them: components added, removed, or moved to another version, and the vulnerabilities and policy violations that came or went with those changes. Use it to review a release before it ships, or to see what a supplier's new version changes before you roll it out.
Compare two SBOMs
Select the SBOMs
Open Attestations and stay on the Imported tab. Select the two SBOMs to compare, for example two versions of the same application.
Select Compare
Compare is available when exactly two SBOMs are selected. The order you select them in doesn't matter: the SBOM created earlier, according to its own metadata, is the old side.
Read the comparison
The top of the page summarizes each SBOM: its file name, when and by which tool it was created, and its vulnerabilities and policy violations by severity.
Below, three tables list only what differs:
| Table | What a row means |
|---|---|
| Components Changed | A package whose versions differ between the SBOMs. Added is only in the newer SBOM, Removed only in the older one, Updated is in both at different versions. |
| Vulnerabilities Changed | Added is found only in the newer SBOM, Resolved only in the older one. |
| Policy Violations Changed | Added is raised only for the newer SBOM, Resolved only for the older one. |
A component at the same version in both SBOMs is left out, and so are its vulnerabilities.
How the comparison is computed
SBOM Observer imports each SBOM on its own into a temporary copy of your namespace. The copy has your current policies and VEX analysis and today's advisory data, but none of your other SBOMs. Both SBOMs are then matched against advisories and evaluated against your policies.
Two things follow from that:
- A difference in the result comes from a difference in the SBOMs. A vulnerability published after the older SBOM was uploaded counts against both, so it doesn't show as added.
- The counts can differ from what the Vulnerabilities and Policy Violations pages show for the same SBOM. Those pages reflect the whole namespace; the comparison looks at each SBOM alone.
Your namespace is not changed by a comparison.
Related
- How-to: Generate and upload SBOMs
- How-to: Analyze vulnerability impact
- Concept: Retention strategy
Collect and monitor vendor SBOMs
Collect SBOMs and VEX from suppliers with Trust Repository, import them into SBOM Observer, and keep track of the vulnerabilities in their software.
Enforce policies in CI/CD
Fail a CI/CD build when an SBOM breaks a policy, with a fail-build action and observer analyze --fail.