Import an SBOM
Import an SBOM to review its vulnerabilities and license information.
Last updated
Was this helpful?
Import an SBOM to review its vulnerabilities and license information.
Fortify SCA parses the file and extracts component and metadata information. When an SBOM contains supported identifiers, such as Package URLs, Fortify SCA enriches matched components. Enrichment can add vulnerability and license information.
The imported SBOM is available for review in the SBOMs space.
This feature is only available for our SCA Enterprise users. Already have an account? Click here to upgrade.
Fortify SCA supports the following SBOM formats:
SPDX JSON (.spdx.json)
CycloneDX (.bom..json .*cdx.json .*cdx.xml .bom..xml)
SPDX emphasizes license and compliance information. CycloneDX emphasizes vulnerability information.
Click Import.

In the Import SBOM dialog, drag one or more SBOM files into the upload area. Alternatively, click Select files and choose the files.
Click Import.
Wait for each file to show an Imported status.
Select View Results to open the imported SBOM.
Select Cancel to close the dialog. The imported SBOM appears in the All tab.
An import can fail for these reasons:
Invalid SBOM format
Missing required fields
Corrupted file
Your organization has reached its limit of 15 uploaded SBOMs.
Review the displayed error. Then verify that the file is valid and complete. To import another SBOM after reaching the limit, delete an existing uploaded SBOM.
Results depend on the quality and completeness of the uploaded SBOM. Fortify SCA does not analyze supplied source code.
Last updated
Was this helpful?
Was this helpful?

