License names that automatically will be assigned to this license type. The selection box is editable.
Recommendation
Recommendation setting for use of software with this license type: Approve/For internal use only/Deny.
Permissiveness
Public domain/Permissive/Weak copyleft/Copyleft/Proprietary.
Use template
Activate the template. Opens a text field for adding template text.
Template
Template license text.
Updated: 2024-12-04 SBOM Central
External artifacts has a Licenses tab in their show page. Licenses are often retrieved from uploaded SBOMs, or external data sources (websites), but you can also add licenses manually.
A manually created license may be modified by pushing the Edit button.
Reports
Updated 2024-12-04 SBOM Central
A modern CI/CD workflow generates SBOMs continuously; however, only a select few are crucial for purposes such as releases, deliveries, traceability, and historical records.
In SBOM Central, these significant SBOMs are highlighted by creating a Delivery Report.
A modern CI/CD workflow generates SBOMs continuously; however, only a select few are crucial for purposes such as releases, deliveries, traceability, and historical records.
In SBOM Central, these significant SBOMs are highlighted by creating a Delivery Report.
A released product should be represented by an SBOM that specifies the product name and version. In SBOM Central, the SBOM is actively monitored for newly discovered vulnerabilities, with notifications automatically triggered upon detection. The "released" SBOM should also include an attached Delivery Report.
Any detected vulnerability must be carefully analyzed, and appropriate actions decided upon. This analysis and decision-making process will be directly tied to the SBOM/Delivery Report and will form the foundation for generating a VEX report.
Open the SBOM show page and select the vulnerabilities tab.
Review and analyze vulnerabilities individually, ensuring each one is thoroughly assessed as required.
When analysis is finished go to the Deliveries tab and push the Generate VEX for the current Delivery report.
Select all vulnerabilities that you want to be included into the VEX report and push Save.
Updated 2024-12-04 SBOM Central
TODO TODO
A modern CI/CD workflow generates SBOMs continuously; however, only a select few are crucial for purposes such as releases, deliveries, traceability, and historical records.
In SBOM Central, these significant SBOMs are highlighted by creating a Delivery Report.
Example: SBOM Central has identified a critical vulnerability in one of your products, and you are required to release an advisory report to your customers. A software update is not necessary, but some configuration changes are required. The following are the steps:
Example: SBOM Central has identified a critical vulnerability in one of your products, and you are required to release an advisory report to your customers. A software update is not necessary, but some configuration changes are required. The following are the steps: