SBOM
The SBOM tab of the application details section displays the application's software bill of materials. The SBOM provides you with a list of dependencies used by your application, along with:
- The dependency version;
- The dependency type;
- The license type;
- The total number of CVEs introduced by the dependency, along with the number of reachable CVEs and the number of exploitable CVEs;
- When the dependency was first identified as present in your application.
If the dependency introduces CVEs, you can click on its name to see a list of all associated vulnerabilities.
data:image/s3,"s3://crabby-images/75acd/75acd949d4f560d0f4c92973f987fb9e5fbf3f92" alt="Dashboard screen showing information that populates the SBOM report"
Export the SBOM
You can export the SBOM generated by preZero in various standards and formats, including:
Standard | Version | Output types |
---|---|---|
CycloneDX | v1.2 | XML and JSON |
CycloneDX | v1.4 | XML and JSON |
SPDX | 2.3 | XML, JSON, tag values |
VEX | 0.2.0 | JSON |
To export the SBOM, click Export. Select the findings type and licenses you'd like included, then click Export Report to select the standard and format of your choice.
data:image/s3,"s3://crabby-images/d5f1f/d5f1f6e5d9e58fcafd2c7a52a5e2c8abaebca419" alt="Dashboard screen showing the SBOM report export options"