Compare two SBOMs

See which components, vulnerabilities, and policy violations changed between two SBOMs, for example two releases of one application.

Comparing two SBOMs shows what changed between them: components added, removed, or moved to another version, and the vulnerabilities and policy violations that came or went with those changes. Use it to review a release before it ships, or to see what a supplier's new version changes before you roll it out.

Compare two SBOMs

Select the SBOMs

Open Attestations and stay on the Imported tab. Select the two SBOMs to compare, for example two versions of the same application.

Select Compare

Compare is available when exactly two SBOMs are selected. The order you select them in doesn't matter: the SBOM created earlier, according to its own metadata, is the old side.

Read the comparison

The top of the page summarizes each SBOM: its file name, when and by which tool it was created, and its vulnerabilities and policy violations by severity.

Below, three tables list only what differs:

TableWhat a row means
Components ChangedA package whose versions differ between the SBOMs. Added is only in the newer SBOM, Removed only in the older one, Updated is in both at different versions.
Vulnerabilities ChangedAdded is found only in the newer SBOM, Resolved only in the older one.
Policy Violations ChangedAdded is raised only for the newer SBOM, Resolved only for the older one.

A component at the same version in both SBOMs is left out, and so are its vulnerabilities.

How the comparison is computed

SBOM Observer imports each SBOM on its own into a temporary copy of your namespace. The copy has your current policies and VEX analysis and today's advisory data, but none of your other SBOMs. Both SBOMs are then matched against advisories and evaluated against your policies.

Two things follow from that:

  • A difference in the result comes from a difference in the SBOMs. A vulnerability published after the older SBOM was uploaded counts against both, so it doesn't show as added.
  • The counts can differ from what the Vulnerabilities and Policy Violations pages show for the same SBOM. Those pages reflect the whole namespace; the comparison looks at each SBOM alone.

Your namespace is not changed by a comparison.