SBOM View
The SBOM view lists the components (third-party dependencies) contained in the vulnerability reports uploaded to the project. It provides a single inventory across all builds, showing one entry per component of the latest uploaded version of each build.
Columns
| Column | Description |
|---|---|
| Build | The build whose SBOM the component was uploaded for. Links to the build details. |
| Name | The component (package) name. |
| Version | The component version. |
| Type | The component type as declared in the SBOM (for example, library, application, container). |
| Package URL | The component's package URL (purl), a canonical identifier of the package. Truncated with a tooltip showing the full value. |
| Licenses | The licenses declared for the component in the SBOM. |
Per-Build SBOM Tab
The components of a single build version are also available on the build details page. When a build version has an uploaded SBOM, an SBOM tab appears there and lists that version's components using the same columns as above, except Build. Builds without an uploaded SBOM (for example, builds imported from JFrog Xray) do not show this tab.
Vulnerabilities and Violations
The SBOM view lists components only. Any vulnerabilities carried by the SBOM are shown on the build details Vulnerabilities tab and, as security violations, in the Violations view. See Uploading Vulnerability Reports → Vulnerabilities for which formats carry vulnerability data.
