sbomify ยท v26.1.0
A Software Bill of Materials (SBOM) and document management platform application.
This is a wellmaintained/packages distribution of the hosted app.sbomify.com service.
7 container images
CycloneDX SBOMs
CycloneDX SBOMs
Grype CVE scans
VEX triage
VEX triage
License notices
Source disclosure
Source disclosure
SLSA Build Level 3
Sigstore signing
Sigstore signing
Regulation Evidence Map
Which release artifacts satisfy specific regulatory requirements.
| Regulation | Control | Dependencies | Vulnerabilities | Licenses | Provenance |
|---|---|---|---|---|---|
| Vendor Security Assessment | Software composition | โ | |||
| Vulnerability management | โ | ||||
| Third-party risk | โ | ||||
| Build integrity | โ | ||||
| ISO 27001 | A.8.8 Vulnerability management | โ | |||
| A.8.28 Secure coding | โ | โ | |||
| A.8.30 Outsourced development | โ | โ | |||
| CRA | Art.13 SBOM requirement | โ | |||
| Art.13(6) Vulnerability handling | โ | ||||
| Art.13 Secure development | โ |