sbomtriageExample
Example workspace. A real scan of a polyglot monorepo with 20 real packages across npm, PyPI, Go, Cargo, NuGet and RubyGems, saved on 2026-09-30. It’s read-only, so nothing here changes a real project.Scan your own software

example-monorepo

grade C · last checked 5 days ago · 1 recent history entry
Example report

Connect your build pipeline

Send an SBOM from CI and keep the security report with your build artefacts.

Set up CI scanning

Project

Name

Shown in the sidebar and in reports.

Rescan schedule

Early access monitoring picks up repository changes automatically.

Each scan checks the stored inventory against OSV again, so it picks up advisories published since the last scan.

Sources

1 of 5
SourceComponentsUpdated
cdx-mixed-ecosystems.json
uploaded
205 days ago

Replacing a source re-analyses the project straight away. Removing one doesn’t: the report keeps the larger inventory until the next scan, so a drop in findings isn’t mistaken for progress.

Danger zone

Delete this project

Deletes its history, its saved report and every decision recorded on it. You can’t undo this.