SBOM
Bring your software bill of materials onto the thread — import CycloneDX or SPDX, track components and vulnerabilities, and propagate suspect on new CVEs.
Import CycloneDX or SPDX and every component becomes a first-class item — linked to the risks it threatens and the tests that cover it, with CVE and CVSS tracking and suspect propagation when a new vulnerability lands. Your supply chain becomes part of the same connected record as everything else.
This section covers importing an SBOM, working with components and vulnerabilities, and governing your supply chain with license policies and suspect propagation.
The supply chain on the same thread as everything else
A software bill of materials is often treated as a document that lives apart from engineering — generated at build time, filed away, and consulted only when a vulnerability makes the news. TraceUnified brings it onto the thread. Import a CycloneDX or SPDX SBOM and every component becomes a first-class item in the same connected record as your requirements, tests, and risks — linked to the risks it threatens and the verification that covers it, not stranded in a separate list.
Components, vulnerabilities, and CVE tracking
Once components are real items, vulnerability management becomes traceable. Each component carries its CVE and CVSS information, so the security posture of your supply chain is visible in context: you can see not just that a component has a known vulnerability, but which parts of your system depend on it and what that means for risk. License policies and attestation extend the same governance to the legal dimension of the supply chain.
Suspect propagation when a new CVE lands
The payoff is what happens when a new vulnerability is disclosed. Because components are linked into the thread, a newly landed CVE propagates suspect status to the items that depend on the affected component — turning a supply-chain event into a specific, actionable list of what to re-examine rather than a manual hunt through a static SBOM. This is FDA-cybersecurity-relevant capability built into the same system as the rest of your evidence.
What’s in this section
- Importing an SBOM — CycloneDX and SPDX
- Components — components as first-class items
- Vulnerabilities — CVE and CVSS tracking
- License policies & attestation — governing your supply chain
- Suspect propagation — reacting when a CVE lands
- Import & triage an SBOM — a step-by-step walkthrough from import to triaged vulnerabilities