Suppliers
Supplier fields from SBOMs and the annotation fields users can edit.
A supplier is an organization or person that supplies, manufactures, or sells software components. Supplier data comes from SBOMs, and users can add to it with annotations.
Supplier fields
Index fields (from SBOMs)
| Field | Type | Description |
|---|---|---|
id | string | Unique identifier for the supplier |
name | string | Supplier name from the SBOM |
type | ORGANIZATION | PERSON | Type of supplier |
address | address | Postal address (see below) |
url | string[] | URLs associated with the supplier |
contact | contact[] | Contact information (see below) |
Annotation fields (user editable)
| Field | Type | Description |
|---|---|---|
displayName | string | Custom name to display instead of the SBOM name |
contact | contact | Primary contact information |
address | address | Organizational postal address |
lei | string | Legal Entity Identifier |
vat | string | VAT number |
eori | string | Economic Operators Registration and Identification |
euid | string | European Unique Identifier |
brn | string | Business Registration Number |
internalId | string | Internal supplier ID or code |
cpeVendor | string | CPE vendor name for matching vulnerabilities |
duns | string | Dun & Bradstreet D-U-N-S Number |
uei | string | Unique Entity Identifier (SAM.gov) |
cage | string | Commercial and Government Entity Code |
gln | string | Global Location Number |
iso6523 | string | ISO 6523 International Code Designator |
notes | string | Free-form notes about the supplier |
tags | string[] | Categorization tags |
properties | object | Key-value properties (and custom fields) |
Contact information
| Field | Type | Description |
|---|---|---|
name | string | Contact person name |
email | string | Email address |
phone | string | Phone number |
Postal address
| Field | Type | Description |
|---|---|---|
country | string | Country name or code |
region | string | State, province, or region |
locality | string | City or locality |
postalCode | string | Postal or ZIP code |
streetAddress | string | Street address |
postOfficeBoxNumber | string | PO Box number |
Supplier annotations
Annotation fields are edited by hand in the UI, and stored apart from the SBOM data. A display name set on the annotation is shown instead of the SBOM's spelling, so one supplier reads the same across SBOMs.
Using supplier data in policies
A component-scoped policy reads supplier data from component.supplier and component.manufacturer, for example to require that every component names a supplier:
function Policy({ component }) {
// require supplier information
if (!component.supplier) {
return [{ message: "Component has no supplier", severity: 7 }];
}
// require an internal ID on the supplier annotation
if (!component.supplier.annotation?.internalId) {
return [{ message: "Supplier has no internal ID", severity: 3 }];
}
return null;
}