Confirm what was delivered
Match the component identity and version to the installed package, build record and supplier information.
Worked example / Software inventory
One gateway. Two releases. Follow a component update through the inventory, its dependency relationships and the questions a release review needs to answer.
CycloneDX 1.6 · JSON · Fictional teaching example
Component identity stays consistent across the two inventories.
An SBOM ties the released product to its components. Stable references let you follow those components through dependency relationships and compare what changed in the next release.
The update client moves from 1.0.0 to 1.1.0. The API, adapter and recorded dependency relationships stay the same.
02 / Review the change
The inventory records a change in the update client. Whether that change addresses a vulnerability depends on the package identity, the deployed build and the evidence for the fix.
The product references all three components. The management API also references the protocol adapter.
Match the component identity and version to the installed package, build record and supplier information.
Check which findings apply to this component and whether their affected-version and configuration conditions still hold.
Use fix information and applicable verification results to decide the next action. Retain the reasoning with the product release.
03 / Source files
Download the CycloneDX inventories used on this page. Inspect the product version, component references and dependency entries in a text editor or SBOM tool.
Fictional names and versions illustrate the structure. Package identifiers and delivery coverage need to be completed for a real product.Further reading
Start with your product architecture, software inventory and existing analysis, then develop the security records you need.
Create a product