Uploading an SBOM file

Upload SBOM files in CycloneDX or SPDX format into IBM® Concert to assess the reliability, maintenance, licensing, and security of the software package components used in your applications.

Before you begin

Before uploading package SBOM files, consider the following guidelines:
  • Define an application, refer to the topic defining an application from SBOM file for detailed steps.
  • Upload one scan file at a time to help ensure correct processing and reduce errors or conflicts.
  • If the size of SBOM is more than 10 MB, you can split the data for that specific image or component to prevent issues with uploading and processing.

Uploading SBOM files

Concert supports JSON files in CycloneDX or SPDX format as SBOM files. There are three ways to upload your SBOM data into Concert. Following are the methods to upload the package SBOM to Concert:

Instructions on uploading SBOM from UI

  1. Click Dimensions > Software composition.
  2. Click Upload CycloneDX or SPDX SBOM from any subnavigation.
  3. Choose if you want to upload SBOM to an Existing Application or New Application.
  4. Choose Source as Image or Source code if you are uploading a CycloneDX file. Otherwise choose Source as Library.
    • If you choose Source as Image, choose an Application name from overflow menu and provide Tag, Digest and Image name.
    • Source as Library, choose an Application name from overflow menu and provide Version and Library name.
    • When you choose Source as Source code, choose an Application name from overflow menu and provide Repository URL, Repository name, Branch name , Scan date and Scan time.
  5. Drag the SBOM file or click to select the file from your directory and click Upload.

Once processing is complete, the package data that is contained in the SBOM appears within the Software composition dimension under Package SBOMs.

All SBOMs are grouped as Correlated or Uncorrelated components. While packages that are listed under Correlated are those with any version or instance of any repository or build artifact that is related to an application or environment, Uncorrelated are vice-versa. You can browse for or search by name of your SBOM from the available list.

Click open the SBOM, and you can check details under the available sub navigation options Overview, OpenSSF scorecard, Recommendations, File view, History, and others.