Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Software Inventory

Build an inventory of applications, components and releases from the SBOMs your pipelines and suppliers produce. It updates on every build, down to the operating system packages inside your containers.

A container SBOM broken down by base image layer, operating system packages and application dependencies.

Software data lives in too many places

The asset database knows application names. The build system knows dependency versions. Supplier documents live somewhere else. Few teams can say what runs where today.

Two pictures of the same software
The CMDB lists applications. The build system knows dependency versions. Neither says what shipped.
Vendor software tracked on the side
Third-party software has its own spreadsheet and owners, and comparing it with internal software means merging lists by hand.
Updated once a quarter
Manual updates lag behind. New versions and components pile up in between.

How it works with SBOM Observer

  1. 1Connect the pipelines

    The Observer CLI uploads an SBOM from each build, so new components show up with the build.

  2. 2Import what you have

    CycloneDX and SPDX exports from SCA and asset tools load alongside, and supplier SBOMs by upload.

  3. 3Search by component

    Find every application and release that ships a component version, with its license and known vulnerabilities.

Health of the projects you depend on

Each open source component shows the OpenSSF Scorecard of its source repository: maintenance, code review, token permissions and more.

OpenSSF Scorecard for the next.js repository, as shown on a component.
OpenSSF Scorecard for the next.js repository, as shown on a component.

Who works with it

Application owners
See what is in each release without waiting for a manual inventory update.
Security and compliance teams
Search the portfolio for a component version without running a new scan.
Vendor management and procurement
See vendor software next to internal builds, with no separate spreadsheet.

Questions

Can we import existing asset data?

Yes, as CycloneDX or SPDX exports from your SCA, CMDB or asset tools.

How current is the inventory?

As current as your pipelines. Each build that runs the Observer CLI uploads its SBOM.

Does it cover containers?

Yes. Container SBOMs are broken down by base image layer, operating system package and application dependency.

Upload an SBOM from your own build

Click through the live demo with example data, or book a demo and bring your own SBOMs.

SBOM Observer attestations: imported CycloneDX SBOMs with their status, type and component count