Supplier SBOMs
CycloneDX 1.0 to 1.7, SPDX 2.x and SPDX 3.0.1. Imported components stay distinct from what SBOMFlow observed in your build. A document newer than this build understands is refused, never misread.
Supplier evidence
Chipset vendors, board-support providers and component suppliers send SBOMs, VEX statements and test evidence. SBOMFlow brings them into the release record, keeps each supplier’s claims apart from what your own build shows, and records who sent what, and when.
What it handles
CycloneDX 1.0 to 1.7, SPDX 2.x and SPDX 3.0.1. Imported components stay distinct from what SBOMFlow observed in your build. A document newer than this build understands is refused, never misread.
OpenVEX and CSAF statements appear beside your findings as context. Where a supplier disagrees with your reviewer, both are visible and your reviewer’s decision stands.
Each supplier’s files are declared with who sent them, when they arrived and what they cover. A file nobody declared is warned about, never quietly used.
When two suppliers claim the same component at different versions, both claims are recorded and shown to a person. Nothing is resolved for you.
Supplier evidence packages — with a validity date, a supersedes reference and a named acceptance — are built and tested, but no command reads them yet, so they are not part of this offering today.
Where a supplier file is normalised, the fingerprint of the original is kept beside it, so you can always show what the supplier sent. A resend under a new name is spotted as a duplicate.
Signatures on the evidence you receive can be checked against a trust policy you write: which signers you accept, for how long, and for what. When a valid signature is still not one you authorised, the record says which reason applies, so “add this signer” never reads like “treat this as suspect”.
What a supplier’s evidence can never do on its own:
Passing evidence the other way — to an importer, a distributor or a customer — is part of the release record: a redaction-audited sharing pack and a no-install auditor package.
Point a run at a real release together with the SBOM or VEX a supplier sent you, and see what agrees, what conflicts and what nobody has accepted yet. It runs offline on your own machine. v0.5.0 is available to approved private testers.