Share SBOMs with customers

Export an SBOM from SBOM Observer, and publish SBOMs and VEX to customers with Trust Repository.

SBOM Observer can export an SBOM for any component or project. To publish SBOMs and VEX to customers, partners, and other parties on an ongoing basis, use Trust Repository.

Export an SBOM

Open the component or project

Open the application, container, or project on its page in SBOM Observer and select Export SBOM.

Choose what to include

  • Format: CycloneDX 1.4, 1.5, or 1.6 (the default), or SPDX 2.3.
  • Include dependencies: on by default.
  • Include vulnerabilities and Include VEX: off by default, and only available for CycloneDX.

Download

Confirm, and the browser downloads the SBOM file.

Publish with Trust Repository

Sending files by email works once, but customers usually need the current SBOM and VEX for each release, and you need to know what each customer received. Trust Repository is the Bytesafe product for that. It keeps SBOMs, VEX statements, and end-of-life dates per release and publishes them through a Trust Portal. Customers and partners fetch documents there and subscribe to updates, and you share with a regulator from the same record when asked. Access groups decide who sees which product, and every download is recorded.

Trust Repository also works in the other direction, collecting SBOMs from your suppliers; see Collect and monitor vendor SBOMs. Product details are at bytesafe.dev/trust.

Next steps