Suppliers

Supplier fields from SBOMs and the annotation fields users can edit.

A supplier is an organization or person that supplies, manufactures, or sells software components. Supplier data comes from SBOMs, and users can add to it with annotations.

Supplier fields

Index fields (from SBOMs)

FieldTypeDescription
idstringUnique identifier for the supplier
namestringSupplier name from the SBOM
typeORGANIZATION | PERSONType of supplier
addressaddressPostal address (see below)
urlstring[]URLs associated with the supplier
contactcontact[]Contact information (see below)

Annotation fields (user editable)

FieldTypeDescription
displayNamestringCustom name to display instead of the SBOM name
contactcontactPrimary contact information
addressaddressOrganizational postal address
leistringLegal Entity Identifier
vatstringVAT number
eoristringEconomic Operators Registration and Identification
euidstringEuropean Unique Identifier
brnstringBusiness Registration Number
internalIdstringInternal supplier ID or code
cpeVendorstringCPE vendor name for matching vulnerabilities
dunsstringDun & Bradstreet D-U-N-S Number
ueistringUnique Entity Identifier (SAM.gov)
cagestringCommercial and Government Entity Code
glnstringGlobal Location Number
iso6523stringISO 6523 International Code Designator
notesstringFree-form notes about the supplier
tagsstring[]Categorization tags
propertiesobjectKey-value properties (and custom fields)

Contact information

FieldTypeDescription
namestringContact person name
emailstringEmail address
phonestringPhone number

Postal address

FieldTypeDescription
countrystringCountry name or code
regionstringState, province, or region
localitystringCity or locality
postalCodestringPostal or ZIP code
streetAddressstringStreet address
postOfficeBoxNumberstringPO Box number

Supplier annotations

Annotation fields are edited by hand in the UI, and stored apart from the SBOM data. A display name set on the annotation is shown instead of the SBOM's spelling, so one supplier reads the same across SBOMs.

Using supplier data in policies

A component-scoped policy reads supplier data from component.supplier and component.manufacturer, for example to require that every component names a supplier:

function Policy({ component }) {
  // require supplier information
  if (!component.supplier) {
    return [{ message: "Component has no supplier", severity: 7 }];
  }
  // require an internal ID on the supplier annotation
  if (!component.supplier.annotation?.internalId) {
    return [{ message: "Supplier has no internal ID", severity: 3 }];
  }
  return null;
}