All references
Lookup pages for the SBOM Observer CLI, data model, policy inputs, and deployment.
Lookup tables and field-level detail. See concepts for how SBOM Observer works, how-to guides for tasks.
Advisory sources
The vulnerability and advisory sources SBOM Observer matches components against.
Air-gapped configuration
Run self-hosted SBOM Observer in a network with no internet access.
Attestation-scoped input
The input an attestation-scoped policy receives, with TypeScript types and a sample.
CLI
Observer CLI commands, flags, and environment variables.
Component-scoped input
The input a component-scoped policy receives, with TypeScript types and a sample.
Data model
Namespaces, attestations, the index, annotations, and mappings, and how they relate.
Ecosystems
Languages, package managers, and operating systems the CLI scans and SBOM Observer analyzes.
Formats and standards
SBOM formats, attestation types, and standards SBOM Observer accepts.
Retention policies
Archive older SBOM versions on upload: the basic policy, CLI flags, and matching rules.
Roles and permissions
Organization roles in SBOM Observer and the permissions each one grants.
Self-hosted installation
Install SBOM Observer in your own infrastructure.
Supplier-scoped input
The input a supplier-scoped policy receives, with TypeScript types and a sample.