Product walkthrough

Inspect one offline evidence run.

This is real SBOMFlow output — a pinned, offline sample run of the bundled example gateway, projected straight from the generated artifacts. No mock dashboard, no invented numbers: change the fixture and this page's figures change with it, or a test fails.

Real output shapes Synthetic sample data · advisories labelled CVE-SAMPLE-*

Interactive product walkthrough · illustrative sample data · advisory data labelled non-real (CVE-SAMPLE-*) · human review required

One offline sbomflow audit of the sample gateway release (Example Embedded Linux Gateway 2.4.1) observes 22 components, matches 2 sample advisory findings (CVE-SAMPLE-OPENSSL-001, CVE-SAMPLE-BUSYBOX-001), maps evidence to the CRA Annex I model, records 7 evidence gaps, and leaves 6 observed items awaiting human review. The release gate stays informational until you enforce a policy — with --fail-on-gaps the same run blocks with the exact reason and exit code 1.

The interactive view needs JavaScript. Everything in it also exists as plain files: see evidence outputs and your first offline audit.

How a reviewer reads this

Six views, one discipline: observed is not reviewed.

Release overview

The release identity, its composition summary, and the state of the evidence — every later view traces back to this one record.

Findings

Each sample finding carries its match confidence and provenance. Notice what's absent: no automatic verdicts, no severity theatre.

CRA coverage

Where observed evidence maps to the Annex I model, where it's manual-only, and where the gaps are — stated as facts, not scores.

Review queue

The observed items a human still has to look at. This queue is the product's honesty made visible: nothing here resolves itself.

Release gate

Informational until a policy is enforced, then explainable: the exact rule, the exact reason, the exact exit code your CI sees.

Release drift

What changed against the previous sample release — added, removed, resolved, still open — the memory that makes evidence compound.

What this sample deliberately is not: proof about any real product, a compliance conclusion, or a hosted dashboard. It is the shape of the files you would own. Run the same thing on your build with your first offline audit, or read the evidence-bundle guide your reviewers would use.

The same run, on your build, this afternoon.

Python 3.11+ and a real build tree — no accounts, no server, nothing sent anywhere. A first audit produces a complete evidence pack in minutes.