SBOM
The SBOM (software bill of materials) is an organization-wide, de-duplicated inventory of the dependencies across your repositories. It shows which packages the organization depends on, under which licenses, and which repositories a compromised package reaches.
Where to Find It
Open SBOM in the dashboard's top navigation. The SBOM is available on the Premium plan; on other plans the tab shows a lock.
How It Is Built
Codity builds the inventory from your manifests and lockfiles, reading them through your Git platform's API. Nothing is cloned. Each build covers up to 500 repositories.
Tabs
| Tab | What it shows |
|---|---|
| Components | Every component in the inventory, sortable by license risk |
| By repository | The inventory for each repository |
| Blast radius | Which repositories carry a given package |
| Zero days | Advisories that have no fix yet |
| Malware | Malicious-package advisories |
| Alerts | Vulnerabilities introduced or fixed between builds, with both open and closed alerts |
What Each Component Shows
- Whether it is a direct or transitive dependency
- Its dependency path
- Its license and license risk
- The OSV advisories that affect it
Exporting
Export the SBOM as:
- CycloneDX 1.6
- SPDX 2.3
- CSV
A per-repository CSV export is also available.
Additional Resources
- Security Scanning: the dependency scan that runs on every pull request
- License Compliance Scanning: license risk and copyleft checks on a pull request

