Release Notes¶
Version 1.0.1 — SBOM360¶
A maintenance release covering the SBOM linking flow and three defects in the Organization portal.
Version 1.0 — SBOM360¶
The first general release of SBOM360. This version covers the complete supply-chain compliance lifecycle across three portals.
Organization portal¶
- Security Dashboard with critical vulnerability counts and pending VEX requests — see Security Dashboard.
- Vendor management: invite vendors, re-send invitations before activation, assign products, set per-vendor SBOM requirements, and manage the vendor lifecycle (deactivate, archive, delete with dependency validation) — see Vendor Management.
- Product management with SBOM linking, version history, and product lifecycle controls — see Product Management.
- Customer management with multiple product deployments per customer and full deployment detail — see Customer Management.
- SBOM management showing source, submitter and product-link status for every SBOM — see SBOM Management.
- Vulnerability queue with CVSS, EPSS and KEV signals, triage status, assignment and VEX overrides — see Vulnerability Queue and Triage.
- Customer notifications to customers and vendors with acknowledgment tracking — see Customer Notifications.
- VEX request inbox for customer requests and vendor submissions — see VEX Request Inbox.
Vendor portal¶
- Guided onboarding, assigned-product visibility, and SBOM submission through the portal or CI/CD — see SBOM Management (Vendor).
- Alert inbox with acknowledgement and status progression — see Alert Inbox.
- VEX statement authoring, including responses to incoming VEX requests — see VEX Statements.
- Profile with company details, logo, notification preferences, API access and account lifecycle requests — see Profile, Settings and API Access.
Customer portal¶
- Deployment registration with environment and version tracking — see My Deployments.
- Security inbox with acknowledge / investigating / patched progression — see Security Inbox.
- VEX requests against a specific deployment — see VEX Requests.
- Profile with contact details, notification preferences and account lifecycle requests — see My Profile.
Platform¶
- SBOM formats: CycloneDX (JSON/XML, v1.2–v1.6) and SPDX (JSON/XML, v2.2–v2.3).
- Automated vulnerability scanning of every submitted SBOM.
- Single sign-on with role-based access control across the three portals.
- Password reset and change-password flows for all three portals.
Documentation versions¶
Each product release has its own copy of this documentation. Use the version selector in the header to switch between them:
| Version | Status | Documentation |
|---|---|---|
| 1.0 | Current | latest (this site) |
The previous version stays online at its own URL, so users on an older release keep working instructions.