Formats and standards
SBOM formats, attestation types, and standards SBOM Observer accepts.
SBOM Observer detects each file's format from its contents, so the file name doesn't matter, with one exception: name an SPDX YAML file .yaml or .yml. A file it can't identify isn't imported; it is listed under the Invalid tab on the Attestations page.
SBOM formats
| Standard | Encodings | Versions |
|---|---|---|
| CycloneDX | JSON, XML | 1.0 to 1.7 |
| SPDX | JSON, YAML, RDF/XML, tag-value | 2.1 to 2.3 |
Observer CLI writes CycloneDX JSON. Files from other tools can be any format above.
VEX and provenance
| Type | What SBOM Observer imports |
|---|---|
| OpenVEX | VEX statements, attached to the vulnerabilities they cover. |
| CycloneDX VEX | The vulnerability analysis inside a CycloneDX document, attached the same way. |
| SLSA provenance | npm provenance attestation bundles, the JSON npm publishes per package version. The provenance is attached to the component it describes, found by package URL or hash, so upload the SBOM first. SBOM Observer also fetches it by itself for the npm components in an imported SBOM, when it has internet access. |
What a CycloneDX document contains
On import, a CycloneDX document is marked with what it contains, shown in the Contents column on the Attestations page.
| Mark | When |
|---|---|
| SBOM | Always, also for SPDX. |
| VEX | Its vulnerabilities carry an analysis. |
| HBOM | A component has a property starting with cdx:device:. |
| CBOM | A component has the type cryptographic-asset. |
| AIBOM | A component has a model card. |