Products

Updated: 2024-11-16 SBOM Central
Updated: 2024-11-21 SBOM Central

An SBOM is a comprehensive inventory of all components and dependencies that make up a version of a software application, library, firmware etc. When such an artifact is registered in SBOM Central, it is assigned a Product identity, i.e. the combination of group (vendor) and name.

Example: An SBOM representing the application com.t2data/epss_cloud@1.3.4 gets the product identity com.t2data/epss_cloud. If the product exists, the artifact will be assigned to it. If not, a new product is created.

In the CycloneDX standard the application is registered in the sections: metadata :: component :: group where the group often is a shortened, single name of the company or project that produced the component, or the source package or domain name & metadata :: component :: name the name of the component.

When opening the product show page, a table presents all artifacts and versions registered by the system.

For SBOMs, the history is also controlled by the collection of Tags.

To have a reference to a previous version of any software, both identity and tag collection must correspond.

Results