SBOM

The SBOM (software bill of materials) is an organization-wide, de-duplicated inventory of the dependencies across your repositories. It shows which packages the organization depends on, under which licenses, and which repositories a compromised package reaches.

Where to Find It

Open SBOM in the dashboard's top navigation. The SBOM is available on the Premium plan; on other plans the tab shows a lock.

How It Is Built

Codity builds the inventory from your manifests and lockfiles, reading them through your Git platform's API. Nothing is cloned. Each build covers up to 500 repositories.

Tabs

Tab What it shows
Components Every component in the inventory, sortable by license risk
By repository The inventory for each repository
Blast radius Which repositories carry a given package
Zero days Advisories that have no fix yet
Malware Malicious-package advisories
Alerts Vulnerabilities introduced or fixed between builds, with both open and closed alerts

What Each Component Shows

  • Whether it is a direct or transitive dependency
  • Its dependency path
  • Its license and license risk
  • The OSV advisories that affect it

Exporting

Export the SBOM as:

  • CycloneDX 1.6
  • SPDX 2.3
  • CSV
  • PDF

A per-repository CSV export is also available.

Additional Resources