Release overview
The release identity, its composition summary, and the state of the evidence — every later view traces back to this one record.
Product walkthrough
This is real SBOMFlow output — a pinned, offline sample run of the bundled example gateway, projected straight from the generated artifacts. No mock dashboard, no invented numbers: change the fixture and this page's figures change with it, or a test fails.
One offline sbomflow audit of the sample gateway release
(Example Embedded Linux Gateway 2.4.1) observes
22 components, matches 2 sample advisory
findings (CVE-SAMPLE-OPENSSL-001,
CVE-SAMPLE-BUSYBOX-001), maps evidence to the CRA Annex I
model, records 7 evidence gaps, and leaves
6 observed items awaiting human review. The release
gate stays informational until you enforce a policy — with
--fail-on-gaps the same run blocks with the exact reason
and exit code 1.
The interactive view needs JavaScript. Everything in it also exists as plain files: see evidence outputs and your first offline audit.
How a reviewer reads this
The release identity, its composition summary, and the state of the evidence — every later view traces back to this one record.
Each sample finding carries its match confidence and provenance. Notice what's absent: no automatic verdicts, no severity theatre.
Where observed evidence maps to the Annex I model, where it's manual-only, and where the gaps are — stated as facts, not scores.
The observed items a human still has to look at. This queue is the product's honesty made visible: nothing here resolves itself.
Informational until a policy is enforced, then explainable: the exact rule, the exact reason, the exact exit code your CI sees.
What changed against the previous sample release — added, removed, resolved, still open — the memory that makes evidence compound.
What this sample deliberately is not: proof about any real product, a compliance conclusion, or a hosted dashboard. It is the shape of the files you would own. Run the same thing on your build with your first offline audit, or read the evidence-bundle guide your reviewers would use.
Python 3.11+ and a real build tree — no accounts, no server, nothing sent anywhere. A first audit produces a complete evidence pack in minutes.