sbomtriageExample
Example workspace. A real scan of a polyglot monorepo with 20 real packages across npm, PyPI, Go, Cargo, NuGet and RubyGems, saved on 2026-09-30. It’s read-only, so nothing here changes a real project.Scan your own software

example-monorepo

grade C · last checked 5 days ago · 1 recent history entry
Example report

181 findings. 2 upgrades to make first.

Applying all 19 upgrades clears 180 of them. 1 has no fix yet.

Checked
20 of 20
components, 100% coverage
Known exploited
0
on CISA’s KEV list
No fix yet
1
need a mitigation instead
Grade
C 64/100
from published thresholds
Open the fix plan

Before you trust these numbers

What this report couldn’t see

  • sbomtriage analyses the inventory declared in your SBOM. It does not read your source code, so it cannot tell whether a vulnerable function is ever reached or executed.
  • A "Fix now" rating reflects known exploitation or a high predicted exploitation probability. It is not evidence that you have been compromised.
  • Results are only as complete as the SBOM. Components your SBOM generator missed (vendored code, statically linked libraries, bundled assets) are invisible here.
  • Compensating controls, network position, and runtime configuration are not considered. A finding that is unreachable in your deployment will still be listed.
  • Advisory data comes from OSV.dev. Vulnerabilities published very recently, or not covered by OSV for your ecosystem, will not appear.
  • The input contains no dependency graph, so direct and transitive dependencies cannot be distinguished. Lockfiles rarely carry one.
  • No VEX statements were found in this SBOM, so no findings have been ruled out by the vendor. Some listed vulnerabilities may not apply to how the component is used.
  • Severity for advisories published only with a CVSS v4.0 vector is shown qualitatively; no v4 base score is computed rather than presenting an approximation as fact.

How the grade was reached

ReasonCost
Fix-now actions
2 action(s) rated fix now
−16
Fix-soon actions
16 action(s) rated fix soon
−20
No published severity
1 finding(s) have no published severity and were counted as high
0

Every score starts at 100 and loses points against published thresholds. There are no judgement calls, so you can check and dispute every deduction.

How grades work ↗

One square per finding in the latest scan. 3 have a fix and a high chance of being exploited.

  • Fix now 3
  • Fix soon 85
  • Monitor 92
  • No fix 1

What this scan read

Everything found was read and checked
Files read
1
Components
20
Checked
20 100%
Not read
0
1 file
  • cdx-mixed-ecosystems.jsonCycloneDX JSON20 components

Checked against OSV.dev vulnerability database (30 Sept 2026), CISA Known Exploited Vulnerabilities (30 Sept 2026), FIRST EPSS exploit prediction scores (29 Sept 2026).

Do these first

the whole plan (19)
  1. 1
    django3.2.0→5.2.17
    Fix nowclears 37major upgrade
  2. 2
    nokogiri1.11.0→1.19.4
    Fix nowclears 33minor upgrade
  3. 3
    rack2.2.3→2.2.23
    Fix soonclears 32patch upgrade
  4. 4
    Newtonsoft.Json12.0.3→13.0.1
    Fix soonclears 1major upgrade
  5. 5
    ejs3.1.6→3.1.10
    Fix soonclears 2patch upgrade

Applying every upgrade in the full plan clears 180 of 181 findings. The rest have no available fix. 3 need doing now.

What it reads

manage
  • cdx-mixed-ecosystems.json20 components · uploaded

Recently

full history
  • 5 days ago181 appeared