Data model

Namespaces, attestations, the index, annotations, and mappings, and how they relate.

The parts of the SBOM Observer data model:

  • Namespace: holds all data, including configuration such as policies.
  • SBOMs (and other attestations): the main source of data. SBOM Observer keeps every imported SBOM and marks which ones are active and which are archived.
  • The index: built when SBOMs and other attestations are imported ("indexed") into a namespace. It is a graph: components link to their dependencies and to the SBOMs they came from, and suppliers, advisories, and VEX analysis link to the components they concern. All analysis, including policy evaluation, reads from the index.
    • Components are the entries in an SBOM: an application, a container, an open-source package.
    • Suppliers represent organizations or individuals that supply, manufacture, or vend components.
  • Annotations are fields users edit in the app, attached to components, suppliers, and advisories in the index, such as business criticality or an internal supplier ID. They are stored apart from the SBOM data, so the original SBOM stays unchanged.
  • Mappings rename values while SBOMs are indexed, for example to merge spellings of one supplier.

SBOM Observer also adds data from its own datasets to the index: vulnerabilities, open-source package information, and end-of-life dates.

Datasetsvulnerabilities, package info, end of life
SBOMs and other attestationsarchived as uploaded
Indexcomponents, suppliers, links
Annotationsuser data
User interface
Policy engine