Skip to content

Release Notes

Version 1.0.1 — SBOM360

A maintenance release covering the SBOM linking flow and three defects in the Organization portal.


Version 1.0 — SBOM360

The first general release of SBOM360. This version covers the complete supply-chain compliance lifecycle across three portals.

Organization portal

  • Security Dashboard with critical vulnerability counts and pending VEX requests — see Security Dashboard.
  • Vendor management: invite vendors, re-send invitations before activation, assign products, set per-vendor SBOM requirements, and manage the vendor lifecycle (deactivate, archive, delete with dependency validation) — see Vendor Management.
  • Product management with SBOM linking, version history, and product lifecycle controls — see Product Management.
  • Customer management with multiple product deployments per customer and full deployment detail — see Customer Management.
  • SBOM management showing source, submitter and product-link status for every SBOM — see SBOM Management.
  • Vulnerability queue with CVSS, EPSS and KEV signals, triage status, assignment and VEX overrides — see Vulnerability Queue and Triage.
  • Customer notifications to customers and vendors with acknowledgment tracking — see Customer Notifications.
  • VEX request inbox for customer requests and vendor submissions — see VEX Request Inbox.

Vendor portal

  • Guided onboarding, assigned-product visibility, and SBOM submission through the portal or CI/CD — see SBOM Management (Vendor).
  • Alert inbox with acknowledgement and status progression — see Alert Inbox.
  • VEX statement authoring, including responses to incoming VEX requests — see VEX Statements.
  • Profile with company details, logo, notification preferences, API access and account lifecycle requests — see Profile, Settings and API Access.

Customer portal

  • Deployment registration with environment and version tracking — see My Deployments.
  • Security inbox with acknowledge / investigating / patched progression — see Security Inbox.
  • VEX requests against a specific deployment — see VEX Requests.
  • Profile with contact details, notification preferences and account lifecycle requests — see My Profile.

Platform

  • SBOM formats: CycloneDX (JSON/XML, v1.2–v1.6) and SPDX (JSON/XML, v2.2–v2.3).
  • Automated vulnerability scanning of every submitted SBOM.
  • Single sign-on with role-based access control across the three portals.
  • Password reset and change-password flows for all three portals.

Documentation versions

Each product release has its own copy of this documentation. Use the version selector in the header to switch between them:

Version Status Documentation
1.0 Current latest (this site)

The previous version stays online at its own URL, so users on an older release keep working instructions.