sbomtriageExample
Example workspace. A real scan of a polyglot monorepo with 20 real packages across npm, PyPI, Go, Cargo, NuGet and RubyGems, saved on 2026-09-30. It’s read-only, so nothing here changes a real project.Scan your own software

example-monorepo

grade C · last checked 5 days ago · 1 recent history entry
Example report

This is your baseline. You’ll see a comparison after the next scan.

Score over time

higher is better
64 → 64 over 1 scan

Scan history

newest first
WhenChangeGrade
2026-09-30 21:20 UTC
SBOM uploaded
181 appeared385921C

Longest standing

still present in the latest scan
AdvisoryComponentFirst seen
CVE-2022-34265djangoat least 5 days ago
CVE-2023-24580djangoat least 5 days ago
CVE-2018-25032nokogiriat least 5 days ago
CVE-2023-46695djangoat least 5 days ago
CVE-2022-23833djangoat least 5 days ago
CVE-2023-23969djangoat least 5 days ago
CVE-2021-35042djangoat least 5 days ago
CVE-2024-25126rackat least 5 days ago
CVE-2024-21907Newtonsoft.Jsonat least 5 days ago
CVE-2022-29078ejsat least 5 days ago

“No longer present” means the finding is gone from the inventory. Usually it was fixed, but a component can also disappear when a source is removed or a dependency is dropped, so it doesn’t prove anyone fixed it. A first-seen date reads “at least” when the finding was already in the oldest scan we still keep.