Supplier evidence

Take your suppliers’ evidence, not their word for it.

Chipset vendors, board-support providers and component suppliers send SBOMs, VEX statements and test evidence. SBOMFlow brings them into the release record, keeps each supplier’s claims apart from what your own build shows, and records who sent what, and when.

Available today Offline · files you already have
Illustrative brand image, synthetic: a fan of ruled paper forms on an ivory surface, the front sheet carrying an embossed seal
Many documents arrive; each one keeps the name of whoever sent it — illustrative brand image · synthetic

What it handles

Every supplier file, attributed and kept in its place.

Supplier SBOMs

CycloneDX 1.0 to 1.7, SPDX 2.x and SPDX 3.0.1. Imported components stay distinct from what SBOMFlow observed in your build. A document newer than this build understands is refused, never misread.

Supplier VEX

OpenVEX and CSAF statements appear beside your findings as context. Where a supplier disagrees with your reviewer, both are visible and your reviewer’s decision stands.

Who sent what

Each supplier’s files are declared with who sent them, when they arrived and what they cover. A file nobody declared is warned about, never quietly used.

Conflicts stay visible

When two suppliers claim the same component at different versions, both claims are recorded and shown to a person. Nothing is resolved for you.

Built, not yet reachable: evidence packages

Supplier evidence packages — with a validity date, a supersedes reference and a named acceptance — are built and tested, but no command reads them yet, so they are not part of this offering today.

What actually arrived

Where a supplier file is normalised, the fingerprint of the original is kept beside it, so you can always show what the supplier sent. A resend under a new name is spotted as a duplicate.

Signatures on the evidence you receive can be checked against a trust policy you write: which signers you accept, for how long, and for what. When a valid signature is still not one you authorised, the record says which reason applies, so “add this signer” never reads like “treat this as suspect”.

What a supplier’s evidence can never do on its own:

  • Close one of your findings. A supplier’s “not affected” is context for your reviewer, never your status.
  • Pass itself off as something your build showed. Imported claims and observed evidence are kept apart in every output.
  • Count as reviewed. An imported supplier SBOM is recorded as that supplier’s statement; only your own review makes anything accepted.

Passing evidence the other way — to an importer, a distributor or a customer — is part of the release record: a redaction-audited sharing pack and a no-install auditor package.

Bring the supplier file you trust least.

Point a run at a real release together with the SBOM or VEX a supplier sent you, and see what agrees, what conflicts and what nobody has accepted yet. It runs offline on your own machine. v0.5.0 is available to approved private testers.