What problem does it solve?
SBOMs and VEX documents often look “complete” at a glance but miss required fields, contain ambiguous vulnerability status, and hide transitive dependency and licensing risks—creating blind spots in security and compliance decisions.
Core Features & Use Cases
- Validate SBOM completeness vs NTIA minimum elements: checks whether required supplier, component, version, identifier, and dependency relationship data is actually present.
- Interpret VEX (CSAF-based) status correctly: summarizes Not Affected / Affected / Fixed / Under Investigation outcomes and surfaces justification categories that must be auditable.
- Assess transitive dependency and license conflict risk: builds dependency depth/risk concentration signals and flags license posture issues that could block distribution.
Example use case: when a vendor shares a CycloneDX 1.5 or SPDX 2.3 SBOM plus a VEX document, you can quickly determine whether the SBOM meets NTIA minimum elements, whether the VEX “not affected” justifications are credible, which transitive dependencies carry the most risk, and whether any license conflicts require legal review.
Quick Start
Provide your CycloneDX or SPDX SBOM file (and any accompanying CSAF VEX document) and ask the agent to produce an SBOM completeness and VEX interpretation report with transitive dependency risk and license conflict findings.