Formats and standards

SBOM formats, attestation types, and standards SBOM Observer accepts.

SBOM Observer detects each file's format from its contents, so the file name doesn't matter, with one exception: name an SPDX YAML file .yaml or .yml. A file it can't identify isn't imported; it is listed under the Invalid tab on the Attestations page.

SBOM formats

StandardEncodingsVersions
CycloneDXJSON, XML1.0 to 1.7
SPDXJSON, YAML, RDF/XML, tag-value2.1 to 2.3

Observer CLI writes CycloneDX JSON. Files from other tools can be any format above.

VEX and provenance

TypeWhat SBOM Observer imports
OpenVEXVEX statements, attached to the vulnerabilities they cover.
CycloneDX VEXThe vulnerability analysis inside a CycloneDX document, attached the same way.
SLSA provenancenpm provenance attestation bundles, the JSON npm publishes per package version. The provenance is attached to the component it describes, found by package URL or hash, so upload the SBOM first. SBOM Observer also fetches it by itself for the npm components in an imported SBOM, when it has internet access.

What a CycloneDX document contains

On import, a CycloneDX document is marked with what it contains, shown in the Contents column on the Attestations page.

MarkWhen
SBOMAlways, also for SPDX.
VEXIts vulnerabilities carry an analysis.
HBOMA component has a property starting with cdx:device:.
CBOMA component has the type cryptographic-asset.
AIBOMA component has a model card.