Getting started
sbomtriage reads a list of what’s in your software, checks each component against published vulnerability data, and gives you a short, ordered list of upgrades. These pages cover how to use it. The method page explains how the order is decided.
Scan a file without an account
- Open Scan a file and drop in an SBOM, or your lockfiles and manifests. If you add several files, they’re merged into one inventory. See what you can upload.
- You’ll see the scan’s steps on screen. It usually takes a few seconds.
- The report opens with the upgrades to make first. Each row shows what to upgrade, the target version, how many findings it clears, and why it’s in its tier.
The report is kept for 24 hours at an unguessable address, then deleted. Until then, anyone with the address can open it, so share it with care. From the report you can delete it sooner, export it, or sign in to keep a copy as a project.
Keep a project
A project is a piece of software you want to keep watching. It can combine a GitHub repository with up to 5 uploaded sources, such as an SBOM of the container image built from it. Every scan analyses them together as one inventory.
- Sign in with any of the methods offered. Which ones you see depends on what this deployment has enabled.
- Answer four short questions, once: company, role, what you’re scanning, and whether we may contact you. That gives you early access, free of charge: 10 projects, 90 days of history, branded reports and every export.
- Create a project by uploading a file to it, or by connecting a repository.
Every night, the latest CISA KEV and FIRST EPSS data is applied to a project’s existing findings. A finding that becomes known exploited moves up without waiting for a full scan. A full rescan also picks up newly published advisories. It runs weekly, monthly or never, as you choose, and whenever you press Rescan.
Inside a project you can mute a finding (you must give a reason, and it appears in every export), tick an upgrade off once it’s done, and see what changed between scans. Deleting the project or your account deletes everything stored for it.
Connect a GitHub repository
- From Projects, choose Connect a repository.
- GitHub asks where to install the sbomtriage App and which repositories it can read. Pick only the ones you want scanned.
- Back in sbomtriage, you’ll see the repositories you granted. Choose one and it’s read and scanned straight away.
The GitHub App page explains what the App can and can’t see.
What it can’t tell you
A report says which of your declared components are known to be vulnerable, and in what order to fix them. It can’t tell whether the vulnerable code is reachable in your product, and it only knows about components that are in the file. It isn’t an audit, and it doesn’t make anything compliant. The method page lists these limits in full.