Release notes

Product changes and additions to SBOM Observer.

RSS feed

October 2026

The documentation moves to docs.bytesafe.dev

SBOM Observer's documentation now lives at docs.bytesafe.dev, next to the docs for the other Bytesafe products. Links to docs.sbom.observer lead to the matching page here.

improvedSupport for SBOM Observer is now support@bytesafe.dev, the address for every Bytesafe product. Email to the previous SBOM Observer support address still reaches us. See Support.
newGuides to compare two SBOMs and to evaluate open source components with OSS Insights.

April 2026

Compare two SBOMs

Select two SBOMs on the Attestations page and see what changed between them: which components were added, removed, or moved to another version, and which vulnerabilities and policy violations came or went with them.

Both SBOMs are checked against today's advisory data and your current policies. A difference in the result comes from a difference in the SBOMs.

newCompare two SBOMs, for example two releases of your application, or a supplier's new version against the one you run.

March 2026

CycloneDX 1.7

SBOM Observer imports CycloneDX 1.7. An SBOM can now say how far it may be shared, with a Traffic Light Protocol (TLP) marking, and your policies can read it.

improvedImport CycloneDX 1.7 SBOMs. The TLP distribution constraint is available to attestation-scoped policies.

February 2026

An organization can now split its SBOMs and policies into several namespaces, for example one per product line. Switch between them in the sidebar. To try something out without touching real data, open a scratch namespace; it is deleted after a period of inactivity.

The dashboard shows how your vulnerabilities, policy violations, and EPSS scores change over time, and how many attestations, components, and suppliers you track.

improvedAn access token works only in the namespace it was created in.
improvedDownload a table as CSV, Excel, or Markdown, with the columns you have chosen to show. SBOM Observer remembers that choice in your browser.
newAdd a namespace from the namespace switcher or in Settings, where you can also delete one. Roles decide who can do both.
newTrend charts on the dashboard: vulnerabilities and policy violations by severity, EPSS, and the size of your inventory, over a period you choose.
newSupplier-scoped policies run once per supplier, with the vulnerabilities of all its components as input.
newAnnotate components with your own data, as you already could for suppliers, without changing the SBOM. Policies receive the annotations. Components also carry end-of-life dates from the SBOM.
newCycloneDX SBOMs that describe machine learning models are marked AIBOM. The model card shows on the component page, and a Model Insights tab adds the model's data from Hugging Face.

January 2026

Vulnerability details in one place

A vulnerability's page gains a Details tab with the full advisory record: severity, CVSS vector, EPSS, CWE IDs, the vulnerable and patched versions, and references, next to the VEX analysis recorded for the component. Each advisory's page lists the vulnerabilities it matched in your namespace.

improvedVulnerability pages show the advisory and the VEX analysis next to the Impact and Graph tabs.

December 2025

Supplier details you control

Add what an SBOM leaves out about a supplier: who to contact, the contract number, how critical the supplier is to you, and fields of your own. Your additions are stored next to the SBOM data, never written into it, so the original stays intact.

improvedThe component page has an OSS Insights tab for the open source project behind a package: repository activity, the OpenSSF Scorecard, and SLSA provenance. See Evaluate open source components.
improvedUpload compressed files: a gzip file, or a zip archive with several attestations. Observer CLI 0.17.0 compresses files before uploading them.
newSupplier annotations: contacts, contract numbers, criticality, and links per supplier.
newCustom fields give a property your organization uses its own label and form on the supplier page.
newCrisp.chat joins the sub-processors as an optional provider of support chat. It receives data only if you use the chat.

November 2025

Sign in with GitHub, Microsoft, or a passkey

improvedSign in with a GitHub or Microsoft account as well as Google, or with a passkey.

October 2025

Suppliers

A Suppliers page lists the organizations and people named as supplier or manufacturer of the components in your SBOMs.

newSuppliers in the main navigation, each with the components it supplies.
newArchive older versions of an SBOM as you upload a new one with a retention policy: observer upload -p basic, in Observer CLI 0.16.0.