Take an SBOM and manage vulnerability advisories

Record the software components of the running server, import vulnerability advisories, and waive a risk for a limited time.

Required permission: Operator (take SBOM); Release manager (import advisories); Independent approver (waive)

Before you begin

A bill of materials (SBOM) lists every software component the server uses, with its version and licence. Advisories are published vulnerabilities for components. A release is blocked when its SBOM matches a high or critical advisory that nobody has waived.

Platform makes no outbound request for advisories. You import them yourself.

Take an SBOM

  1. Open Platform > Configuration > Bills of materials.
  2. Press Take an SBOM now. The system reads the Python and npm components of the running server.
  3. Open the new row. The columns show when it was taken, the commit, the components, vulnerable and blocking counts, licence flags and the digest.

The Findings tab lists each vulnerability or licence problem and whether it blocks a release. The Components tab lists ecosystem, name, version, licence and whether the component is direct. Licence flags mark unknown or copyleft licences.

Press Download CycloneDX to save the SBOM as sbom-<digest>.cdx.json. The platform.sbom job takes one weekly (Sunday 03:30) once you enable it.

To attach an SBOM to a release, use the release's Evidence tab: Take and attach an SBOM.

Import advisories

  1. A release manager opens Platform > Configuration > Vulnerability advisories and presses Import OSV advisories.
  2. Paste the JSON: one record, a list of up to 5,000, or {"vulns": [...]}. Plain rows need ref, ecosystem (pypi or npm), package, affected, fixed and severity.
  3. Press OK.

The result says how many were created. A second import of the same advisory updates it. Typical refusals:

MessageMeaning
'Send OSV records - one, a list of up to 5,000, or {"vulns": [...]}.'The JSON was empty.
'pypi or npm.'The ecosystem is not supported.
'Every advisory has an id (CVE-..., GHSA-..., PYSEC-...).'The record has no reference.
'low, moderate, high or critical.'The severity is not recognised.

If you paste text that is not valid JSON, the browser's own parse message is shown.

Waive an advisory

  1. An independent approver finds the advisory in the list and presses Waive.
  2. Enter Why the risk is accepted (required) and Waiver ends, a date and time in the future.
  3. Press OK.

The advisory shows Waived (until ...) and stops blocking releases until that time. 'The waiver must end in the future.' appears for a past date. Lift waiver makes it block again.

Worked example. An imported advisory marks requests below version 9.0 as high severity. The SBOM shows a blocking finding and a release is refused with '... 1 unwaived high or critical advisory(ies) in the SBOM.' The approver waives it for 30 days with the reason 'Not reachable in our deployment', and the release can be submitted. The advisories are re-checked when the gate runs.

Good to know

  • The release gate checks the SBOM attached to the release. Take a fresh one if the components have changed.
  • Waivers are time-limited on purpose. Review them before they end.