Upload Software Bill of Materials files manually
Upload Software Bill of Materials (SBOM) files manually.
Before you begin
Starting with version 4.0, SBOM Core supports:
- XML and JSON in versions 1.0 - 1.6 of CycloneDX.
- JSON in versions 2.2 - 2.3 of SPDX.
Role required: sn_sbom_core.sbom_ingest
Procedure
Upload files manually.
The method you use to upload your files depends on whether you have the SBOM Core or SBOM Response applications installed.
| Option | Description |
|---|---|
| If you have installed SBOM Core |
You can upload one SBOM file at a time.
The file name is displayed on the Choose an attachment file page.
|
| If you have installed SBOM Response starting with v4.0 |
The Upload SBOM file modal is displayed.
After your file uploads, a link for the file is displayed along with three icons that provide you with the following options:
You can upload one SBOM file at a time.
These values help you associate this SBOM to a business application or product model in your organization. This information is displayed on the BOM entity record after upload.
The BOM queue page is displayed and the file is listed on the SBOM ingestion section along with upload status other information about the file. |
Upload SBOM files imported by the Veracode Vulnerability Integration.
Note: You can upload Veracode files in CycloneDX (JSON and XML) and SPDX (XML) formats only if you have installed and activated the Veracode integration with Application Vulnerability Response. See the Veracode Vulnerability Integration for more information.
Result
After an SBOM is successfully processed, where you view the upload status depends on the applications you are using.
- If you are using SBOM Response, the BOM Entity record is displayed on the SBOM Ingestion Status list in the BOM Queue module in the SBOM Workspace.
- If you are using SBOM Core, navigate to SBOM Core > BOM Ingestion Status.
Related topics