
Risk and quality on every release
Component count, SBOM quality issues, vulnerabilities and licenses per release.
Each SBOM is checked against the CISA minimum elements, BSI TR-03183-2 (the CRA guideline) and SPDX license rules. Missing producers, missing hashes and invalid license identifiers show up as quality issues on the release.




