[{"data":1,"prerenderedAt":1268},["ShallowReactive",2],{"navigation_docs":3,"-guides-export-reports-and-sboms":114,"-guides-export-reports-and-sboms-surround":1263},[4,23,85,99],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started",[9,13,18],{"title":10,"path":6,"stem":11,"icon":12},"Getting started","1.getting-started\u002Findex","i-lucide-rocket",{"title":14,"path":15,"stem":16,"icon":17},"Try the demo","\u002Fgetting-started\u002Ftry-the-demo","1.getting-started\u002F1.try-the-demo","i-lucide-monitor-play",{"title":19,"path":20,"stem":21,"icon":22},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-play",{"title":24,"path":25,"stem":26,"children":27},"Guides","\u002Fguides","2.guides",[28,31,37,42,47,53,58,63,68,74,80],{"title":24,"path":25,"stem":29,"icon":30},"2.guides\u002Findex","i-lucide-map",{"title":32,"path":33,"stem":34,"icon":35,"group":36},"Connect a GitHub repository","\u002Fguides\u002Fconnect-a-github-repository","2.guides\u002F01.connect-a-github-repository","i-lucide-git-branch","Connect a project",{"title":38,"path":39,"stem":40,"icon":41,"group":36},"Analyze a project without GitHub","\u002Fguides\u002Fanalyze-a-project-without-github","2.guides\u002F02.analyze-a-project-without-github","i-lucide-upload",{"title":43,"path":44,"stem":45,"icon":46,"group":36},"Exclude dependency scopes","\u002Fguides\u002Fexclude-dependency-scopes","2.guides\u002F04.exclude-dependency-scopes","i-lucide-filter",{"title":48,"path":49,"stem":50,"icon":51,"group":52},"Scan from GitHub Actions","\u002Fguides\u002Fscan-from-github-actions","2.guides\u002F05.scan-from-github-actions","i-lucide-workflow","Automate",{"title":54,"path":55,"stem":56,"icon":57,"group":52},"Scan from another CI","\u002Fguides\u002Fscan-from-another-ci","2.guides\u002F06.scan-from-another-ci","i-lucide-square-terminal",{"title":59,"path":60,"stem":61,"icon":62,"group":52},"Manage API keys","\u002Fguides\u002Fmanage-api-keys","2.guides\u002F07.manage-api-keys","i-lucide-key-round",{"title":64,"path":65,"stem":66,"icon":67,"group":52},"Create many projects at once","\u002Fguides\u002Fcreate-many-projects-at-once","2.guides\u002F08.create-many-projects-at-once","i-lucide-layers",{"title":69,"path":70,"stem":71,"icon":72,"group":73},"Export reports and SBOMs","\u002Fguides\u002Fexport-reports-and-sboms","2.guides\u002F11.export-reports-and-sboms","i-lucide-download","Act on the results",{"title":75,"path":76,"stem":77,"icon":78,"group":79},"Organizations and plans","\u002Fguides\u002Forganizations-and-plans","2.guides\u002F13.organizations-and-plans","i-lucide-building-2","Organization and team",{"title":81,"path":82,"stem":83,"icon":84,"group":79},"Invite your team","\u002Fguides\u002Finvite-your-team","2.guides\u002F14.invite-your-team","i-lucide-users",{"title":86,"path":87,"stem":88,"children":89},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[90,94],{"title":91,"path":87,"stem":92,"icon":93},"Core concepts","3.core-concepts\u002Findex","i-lucide-lightbulb",{"title":95,"path":96,"stem":97,"icon":98},"The health score","\u002Fcore-concepts\u002Fhealth-score","3.core-concepts\u002F1.health-score","i-lucide-gauge",{"title":100,"path":101,"stem":102,"children":103},"Reference","\u002Freference","5.reference",[104,107],{"title":100,"path":101,"stem":105,"icon":106},"5.reference\u002Findex","i-lucide-book-marked",{"title":108,"path":109,"stem":110,"children":111,"icon":113},"Supported ecosystems","\u002Freference\u002Fecosystems","5.reference\u002F1.ecosystems\u002Findex",[112],{"title":108,"path":109,"stem":110,"icon":113},"i-lucide-package",{"id":115,"title":69,"body":116,"description":1256,"extension":1257,"links":1258,"meta":1259,"navigation":1260,"path":70,"seo":1261,"stem":71,"__hash__":1262},"docs\u002F2.guides\u002F11.export-reports-and-sboms.md",{"type":117,"value":118,"toc":1242},"minimark",[119,131,138,143,146,154,159,169,172,176,179,254,261,265,285,289,292,302,461,491,497,549,555,622,627,679,684,766,769,782,786,789,792,795,817,823,962,968,1072,1076,1079,1085,1092,1098,1129,1135,1139,1217,1221,1238],[120,121,122,123,127,128,130],"p",{},"The ",[124,125,126],"strong",{},"Exports"," tab turns the analysis on screen into a file: a CSV report you\nconfigure column by column, a Software Bill of Materials (SBOM) in SPDX or CycloneDX, and the dependency\ngraph as JSON or DOT. Open a dashboard, then go to ",[124,129,126],{}," tab.",[120,132,133,134,137],{},"Every export is built in your browser from the analysis already loaded in the dashboard.\nSo the file always matches the analysis you are\nlooking at, including an older one opened from ",[124,135,136],{},"Scan History"," on the project\npage.",[139,140,142],"h2",{"id":141},"build-a-csv-audit-report","Build a CSV audit report",[120,144,145],{},"The tab opens on the CSV configurator: three steps on the left, the column\npicker on the right.",[147,148],"u-color-mode-image",{"alt":149,"className":150,"dark":152,"light":153},"The CSV configurator, with the three export steps on the left and the column picker on the right",[151],"wide-capture","\u002Fimages\u002Fdocs\u002Fguides\u002Fexport-reports-and-sboms-1-csv-configurator-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Fexport-reports-and-sboms-1-csv-configurator-light.webp",[155,156,158],"h3",{"id":157},"_1-scope","1. Scope",[120,160,161,164,165,168],{},[124,162,163],{},"All"," exports every package in the graph, direct and transitive. ",[124,166,167],{},"Direct\nonly"," keeps only the packages your build files declare. Each\nbutton carries its own count, so you know the size of the file before you build\nit.",[120,170,171],{},"This choice applies to the CSV alone. The SBOM and graph exports always carry\nthe full graph.",[155,173,175],{"id":174},"_2-quick-preset","2. Quick preset",[120,177,178],{},"Four presets fill the column selection for you.",[180,181,182,198],"table",{},[183,184,185],"thead",{},[186,187,188,192,195],"tr",{},[189,190,191],"th",{},"Preset",[189,193,194],{},"Columns",[189,196,197],{},"What it answers",[199,200,201,215,228,241],"tbody",{},[186,202,203,209,212],{},[204,205,206],"td",{},[124,207,208],{},"Scores only",[204,210,211],{},"8",[204,213,214],{},"Which packages score badly, and on which dimension.",[186,216,217,222,225],{},[204,218,219],{},[124,220,221],{},"Security focus",[204,223,224],{},"7",[204,226,227],{},"Which packages carry CVEs, and how severe.",[186,229,230,235,238],{},[204,231,232],{},[124,233,234],{},"License focus",[204,236,237],{},"4",[204,239,240],{},"What license each package ships under, and where its source lives.",[186,242,243,248,251],{},[204,244,245],{},[124,246,247],{},"Full export",[204,249,250],{},"36",[204,252,253],{},"Everything the analysis measured.",[120,255,256,257,260],{},"A preset is a starting point, not a mode. Check or uncheck one box afterwards\nand the selection is yours, which the preset row reports as ",[124,258,259],{},"Custom",". That is\nalso what you see when you arrive, since the default selection of 19 columns\nmatches no preset.",[155,262,264],{"id":263},"_3-review-and-export","3. Review and export",[120,266,267,268,272,273,276,277,280,281,284],{},"The file name is built for you, in the form ",[269,270,271],"code",{},"\u003Cproject>-\u003Cpreset>-\u003Cdate>.csv",",\nwith ",[269,274,275],{},"-direct"," inserted before the date when the scope is ",[124,278,279],{},"Direct only",". Edit\nit in place if you need another one, or use the reset control to go back to the\ngenerated name.\nThe counters above the button give the number of rows and columns you are about\nto export. ",[124,282,283],{},"Export CSV"," stays unavailable while no column is selected.",[155,286,288],{"id":287},"the-columns","The columns",[120,290,291],{},"The picker contains 36 columns in six groups. Each group has its own checkbox, so\nyou can select or clear a whole group in one click.\nThe file always uses the order shown below, regardless of the order in which you select the columns.",[120,293,294,297,298,301],{},[124,295,296],{},"General",", all on by default except ",[124,299,300],{},"Not Found Reason",".",[180,303,304,314],{},[183,305,306],{},[186,307,308,311],{},[189,309,310],{},"Column",[189,312,313],{},"What it holds",[199,315,316,334,344,354,364,377,394,418,428,443],{},[186,317,318,323],{},[204,319,320],{},[124,321,322],{},"Package ID",[204,324,325,326,329,330,333],{},"The graph id, ",[269,327,328],{},"group:artifact:version",". An unscoped npm package writes ",[269,331,332],{},"_"," in the group position.",[186,335,336,341],{},[204,337,338],{},[124,339,340],{},"Group ID",[204,342,343],{},"Maven group, npm scope or Composer vendor. Empty for an unscoped npm package.",[186,345,346,351],{},[204,347,348],{},[124,349,350],{},"Artifact ID",[204,352,353],{},"The package name on its own.",[186,355,356,361],{},[204,357,358],{},[124,359,360],{},"Version",[204,362,363],{},"The resolved version.",[186,365,366,371],{},[204,367,368],{},[124,369,370],{},"Depth in Graph",[204,372,373,376],{},[269,374,375],{},"1"," for a package your build files declare, higher for a transitive one.",[186,378,379,384],{},[204,380,381],{},[124,382,383],{},"License Name",[204,385,386,387,390,391,301],{},"Every license the package declares, joined with ",[269,388,389],{},"\u002F",", or ",[269,392,393],{},"Unknown",[186,395,396,401],{},[204,397,398],{},[124,399,400],{},"License Type",[204,402,403,406,407,406,410,413,414,417],{},[269,404,405],{},"permissive",", ",[269,408,409],{},"weak copyleft",[269,411,412],{},"strong copyleft"," or ",[269,415,416],{},"unknown",". For a package with multiple licenses, this is the most permissive one.",[186,419,420,425],{},[204,421,422],{},[124,423,424],{},"Repository URL",[204,426,427],{},"The source repository, empty when the analysis found none.",[186,429,430,435],{},[204,431,432],{},[124,433,434],{},"Release Found",[204,436,437,413,440,301],{},[269,438,439],{},"true",[269,441,442],{},"false",[186,444,445,449],{},[204,446,447],{},[124,448,300],{},[204,450,451,406,454,390,457,460],{},[269,452,453],{},"PACKAGE_UNKNOWN",[269,455,456],{},"VERSION_UNKNOWN",[269,458,459],{},"UNSPECIFIED"," when the analysis marked the package without naming a cause. Empty for a package that resolved.",[120,462,463,466,467,406,470,406,473,406,476,406,479,482,483,486,487,490],{},[124,464,465],{},"Scores",", all on by default. ",[124,468,469],{},"Overall Score",[124,471,472],{},"Activity Score",[124,474,475],{},"Security\nScore",[124,477,478],{},"Popularity Score",[124,480,481],{},"Community Score"," and ",[124,484,485],{},"Maintainability Score","\neach hold that package's score from 0 to 10.\n",[488,489,95],"a",{"href":96}," explains what goes into them.",[120,492,493,496],{},[124,494,495],{},"Security",", all on by default.",[180,498,499,507],{},[183,500,501],{},[186,502,503,505],{},[189,504,310],{},[189,506,313],{},[199,508,509,519,529,539],{},[186,510,511,516],{},[204,512,513],{},[124,514,515],{},"Total CVEs",[204,517,518],{},"Number of vulnerabilities found on this version.",[186,520,521,526],{},[204,522,523],{},[124,524,525],{},"High CVEs",[204,527,528],{},"Number of vulnerabilities rated high.",[186,530,531,536],{},[204,532,533],{},[124,534,535],{},"Moderate CVEs",[204,537,538],{},"Number of vulnerabilities rated moderate.",[186,540,541,546],{},[204,542,543],{},[124,544,545],{},"Low CVEs",[204,547,548],{},"Number of vulnerabilities rated low.",[120,550,551,554],{},[124,552,553],{},"Activity",", all off by default.",[180,556,557,565],{},[183,558,559],{},[186,560,561,563],{},[189,562,310],{},[189,564,313],{},[199,566,567,577,587,597,610],{},[186,568,569,574],{},[204,570,571],{},[124,572,573],{},"Release Frequency (days)",[204,575,576],{},"Average number of days between two releases.",[186,578,579,584],{},[204,580,581],{},[124,582,583],{},"Commits (1 year)",[204,585,586],{},"Number of commits on the source repository over the last 12 months.",[186,588,589,594],{},[204,590,591],{},[124,592,593],{},"Versions (1 year)",[204,595,596],{},"Number of distinct versions of this package published over the last 12 months, not of the version on the row.",[186,598,599,604],{},[204,600,601],{},[124,602,603],{},"Last Commit Date",[204,605,606,607,301],{},"Date of the last commit, as ",[269,608,609],{},"YYYY-MM-DD",[186,611,612,617],{},[204,613,614],{},[124,615,616],{},"Last Release Date",[204,618,619,620,301],{},"Date of the last release, as ",[269,621,609],{},[120,623,624,554],{},[124,625,626],{},"Popularity",[180,628,629,637],{},[183,630,631],{},[186,632,633,635],{},[189,634,310],{},[189,636,313],{},[199,638,639,649,659,669],{},[186,640,641,646],{},[204,642,643],{},[124,644,645],{},"GitHub Stars",[204,647,648],{},"Number of stars on the source repository.",[186,650,651,656],{},[204,652,653],{},[124,654,655],{},"GitHub Watchers",[204,657,658],{},"Number of watchers on the source repository.",[186,660,661,666],{},[204,662,663],{},[124,664,665],{},"Library Dependents",[204,667,668],{},"Number of other libraries that depend on this package.",[186,670,671,676],{},[204,672,673],{},[124,674,675],{},"Release Dependents",[204,677,678],{},"Number of other releases that depend on this exact version.",[120,680,681,554],{},[124,682,683],{},"Community & Maintainability",[180,685,686,694],{},[183,687,688],{},[186,689,690,692],{},[189,691,310],{},[189,693,313],{},[199,695,696,706,716,726,736,746,756],{},[186,697,698,703],{},[204,699,700],{},[124,701,702],{},"Contributors",[204,704,705],{},"Number of unique contributors on the source repository.",[186,707,708,713],{},[204,709,710],{},[124,711,712],{},"Forks",[204,714,715],{},"Number of forks of the source repository.",[186,717,718,723],{},[204,719,720],{},[124,721,722],{},"Total Issues",[204,724,725],{},"Number of issues on the source repository, open and closed.",[186,727,728,733],{},[204,729,730],{},[124,731,732],{},"Direct Dependencies",[204,734,735],{},"Number of packages this package declares itself.",[186,737,738,743],{},[204,739,740],{},[124,741,742],{},"Transitive Dependencies",[204,744,745],{},"Number of packages it pulls in below those.",[186,747,748,753],{},[204,749,750],{},[124,751,752],{},"Outdated (days)",[204,754,755],{},"How far behind the latest release this version is, in days.",[186,757,758,763],{},[204,759,760],{},[124,761,762],{},"Missed Releases",[204,764,765],{},"How many versions behind the latest this version is.",[120,767,768],{},"Four things to know before you open the file:",[770,771,772,776,779],"ul",{},[773,774,775],"li",{},"One row per package, and no row for your own project.",[773,777,778],{},"The file includes a UTF-8 byte order mark**.",[773,780,781],{},"A package that Deptools could not resolve is exported with empty score cells.",[139,783,785],{"id":784},"export-an-sbom","Export an SBOM",[120,787,788],{},"A Software Bill of Materials (SBOM) is an inventory of the software components shipped with your product. Customers, auditors, and regulators may ask you to provide one, and SBOMs are increasingly part of software security and compliance requirements.",[120,790,791],{},"In the EU, the Cyber Resilience Act (CRA) requires manufacturers to document the software components and dependencies in their products. An SBOM provides this information in a machine-readable form.\nIn the US, Executive Order 14028 helped establish SBOMs as part of federal software security requirements. The published minimum elements reference formats such as SPDX and CycloneDX. Exact requirements vary by regulation, agency, and contract.",[120,793,794],{},"Deptools exports the full dependency graph, not just the top-level dependencies.",[120,796,797,798,801,802,805,806,482,809,812,813,816],{},"Every package includes a ",[269,799,800],{},"purl"," in both formats, ",[269,803,804],{},"pkg:maven\u002Fgroup\u002Fartifact@version",",\n",[269,807,808],{},"pkg:npm\u002Fname@version",[269,810,811],{},"pkg:npm\u002F%40scope\u002Fname@version"," for a scoped package,\n",[269,814,815],{},"pkg:composer\u002Fvendor\u002Fpackage@version",". That is the identifier most tools key on.",[120,818,819,822],{},[124,820,821],{},"SPDX 2.3",", from the Linux Foundation, is the inventory format, for\nprocurement, legal review and audits. It has no field for vulnerabilities.",[180,824,825,835],{},[183,826,827],{},[186,828,829,832],{},[189,830,831],{},"Field",[189,833,834],{},"What Deptools writes",[199,836,837,855,865,875,903,920,933,945],{},[186,838,839,847],{},[204,840,841,406,844],{},[269,842,843],{},"spdxVersion",[269,845,846],{},"dataLicense",[204,848,849,482,852,301],{},[269,850,851],{},"SPDX-2.3",[269,853,854],{},"CC0-1.0",[186,856,857,862],{},[204,858,859],{},[269,860,861],{},"documentNamespace",[204,863,864],{},"Your project name and a UUID generated for that file.",[186,866,867,872],{},[204,868,869],{},[269,870,871],{},"creationInfo",[204,873,874],{},"The creation date and Deptools as the tool.",[186,876,877,882],{},[204,878,879],{},[269,880,881],{},"packages[]",[204,883,884,885,888,889,892,893,896,897,899,900,301],{},"One entry per package: name, ",[269,886,887],{},"versionInfo",", the graph id as ",[269,890,891],{},"packageFileName",", the repository URL as ",[269,894,895],{},"downloadLocation",", and its ",[269,898,800],{}," under ",[269,901,902],{},"externalRefs",[186,904,905,913],{},[204,906,907,406,910],{},[269,908,909],{},"licenseConcluded",[269,911,912],{},"licenseDeclared",[204,914,915,916,919],{},"The license names, or ",[269,917,918],{},"NOASSERTION"," when the analysis found none.",[186,921,922,927],{},[204,923,924],{},[269,925,926],{},"supplier",[204,928,929,930,932],{},"The group, npm scope or Composer vendor, ",[269,931,918],{}," when the package has none.",[186,934,935,940],{},[204,936,937],{},[269,938,939],{},"filesAnalyzed",[204,941,942,944],{},[269,943,442],{},". The document describes packages, not the files inside them.",[186,946,947,952],{},[204,948,949],{},[269,950,951],{},"relationships[]",[204,953,954,957,958,961],{},[269,955,956],{},"DESCRIBES"," from the document to every package, then ",[269,959,960],{},"DEPENDS_ON"," for every edge of the graph.",[120,963,964,967],{},[124,965,966],{},"CycloneDX 1.5",", from OWASP, is the security format, and the only one of the\ntwo that carries the CVEs.",[180,969,970,978],{},[183,971,972],{},[186,973,974,976],{},[189,975,831],{},[189,977,834],{},[199,979,980,998,1011,1021,1052,1062],{},[186,981,982,990],{},[204,983,984,406,987],{},[269,985,986],{},"bomFormat",[269,988,989],{},"specVersion",[204,991,992,482,995,301],{},[269,993,994],{},"CycloneDX",[269,996,997],{},"1.5",[186,999,1000,1005],{},[204,1001,1002],{},[269,1003,1004],{},"serialNumber",[204,1006,1007,1010],{},[269,1008,1009],{},"urn:uuid:"," and a UUID generated for that file.",[186,1012,1013,1018],{},[204,1014,1015],{},[269,1016,1017],{},"metadata",[204,1019,1020],{},"The creation date, Deptools as the tool, and your project as the described component.",[186,1022,1023,1028],{},[204,1024,1025],{},[269,1026,1027],{},"components[]",[204,1029,1030,1031,1034,1035,406,1038,406,1041,1044,1045,1047,1048,1051],{},"One ",[269,1032,1033],{},"library"," per package, with ",[269,1036,1037],{},"group",[269,1039,1040],{},"name",[269,1042,1043],{},"version",", its ",[269,1046,800],{},", its licenses when they are known, and the repository URL as a ",[269,1049,1050],{},"vcs"," external reference.",[186,1053,1054,1059],{},[204,1055,1056],{},[269,1057,1058],{},"dependencies[]",[204,1060,1061],{},"What each package pulls in, plus one entry for your project holding your direct dependencies.",[186,1063,1064,1069],{},[204,1065,1066],{},[269,1067,1068],{},"vulnerabilities[]",[204,1070,1071],{},"One entry per CVE, with its identifier, its severity, the CWE identifiers when the analysis has them, and the version affected. The key is absent when no CVE was found.",[139,1073,1075],{"id":1074},"export-the-graph","Export the graph",[120,1077,1078],{},"Two more formats, for when you want the data rather than a report.",[120,1080,1081,1084],{},[124,1082,1083],{},"Graph JSON"," holds the nodes and edges the dashboard renders, unchanged. A\nnode carries its id, version, depth, licenses, repository URL and one block per\ndimension with the raw metrics. An edge carries its source, its target, the version range that was\ndeclared, the version that was resolved, and the scope the dependency was\ndeclared in. The graph-level scores and the analysis errors are not in the file.",[120,1086,1087,1088,1091],{},"The payload holds one node your build files never declared, ",[269,1089,1090],{},"ROOT:ROOT:ROOT",". It\nstands for your project, and it is the source of one edge per direct dependency.\nSkip that node and its edges in a script, or every count you compute includes a\npackage that does not exist.",[120,1093,1094,1097],{},[124,1095,1096],{},"Graphviz DOT"," renders in one command:",[1099,1100,1105],"pre",{"className":1101,"code":1102,"language":1103,"meta":1104,"style":1104},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","dot -Tsvg my-project-graph-2026-08-16.dot -o graph.svg\n","bash","",[269,1106,1107],{"__ignoreMap":1104},[1108,1109,1112,1116,1120,1123,1126],"span",{"class":1110,"line":1111},"line",1,[1108,1113,1115],{"class":1114},"sBMFI","dot",[1108,1117,1119],{"class":1118},"sfazB"," -Tsvg",[1108,1121,1122],{"class":1118}," my-project-graph-2026-08-16.dot",[1108,1124,1125],{"class":1118}," -o",[1108,1127,1128],{"class":1118}," graph.svg\n",[120,1130,1131,1132,1134],{},"Each box is labeled with the readable package name and its version.\nThe fill color reflects the overall score: green at 8 or above, yellow at 6 or above, orange at 4 or above, and red below 4, and gray for a package that could not be resolved, which has no score at all. The\n",[269,1133,1090],{}," node is written into the file but the edges leaving it are not,\nso your project shows up as an isolated box and each direct dependency starts a\ntree of its own. Delete that one line if you want it gone.",[139,1136,1138],{"id":1137},"which-format-for-which-need","Which format for which need",[180,1140,1141,1151],{},[183,1142,1143],{},[186,1144,1145,1148],{},[189,1146,1147],{},"What you need",[189,1149,1150],{},"What to export",[199,1152,1153,1163,1172,1181,1190,1199,1208],{},[186,1154,1155,1158],{},[204,1156,1157],{},"A spreadsheet to review with your team",[204,1159,1160,1161],{},"CSV, preset ",[124,1162,247],{},[186,1164,1165,1168],{},[204,1166,1167],{},"Vulnerability triage, by severity",[204,1169,1160,1170],{},[124,1171,221],{},[186,1173,1174,1177],{},[204,1175,1176],{},"A license inventory for legal review",[204,1178,1160,1179],{},[124,1180,234],{},[186,1182,1183,1186],{},[204,1184,1185],{},"An SBOM for procurement, an audit or a regulatory requirement",[204,1187,1188],{},[124,1189,821],{},[186,1191,1192,1195],{},[204,1193,1194],{},"An SBOM for a security tool, CVEs included",[204,1196,1197],{},[124,1198,966],{},[186,1200,1201,1204],{},[204,1202,1203],{},"Your own script, or a comparison between two scans",[204,1205,1206],{},[124,1207,1083],{},[186,1209,1210,1213],{},[204,1211,1212],{},"A picture of the tree for a review or a slide",[204,1214,1215],{},[124,1216,1096],{},[139,1218,1220],{"id":1219},"next-steps","Next steps",[770,1222,1223,1228,1233],{},[773,1224,1225,1227],{},[488,1226,14],{"href":15}," to download each file before you\nconnect a repository.",[773,1229,1230,1232],{},[488,1231,95],{"href":96}," for what the score columns\nmeasure.",[773,1234,1235,1237],{},[488,1236,43],{"href":44}," since every\nexport uses exactly the graph your scope selection produced.",[1239,1240,1241],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":1104,"searchDepth":1243,"depth":1243,"links":1244},2,[1245,1252,1253,1254,1255],{"id":141,"depth":1243,"text":142,"children":1246},[1247,1249,1250,1251],{"id":157,"depth":1248,"text":158},3,{"id":174,"depth":1248,"text":175},{"id":263,"depth":1248,"text":264},{"id":287,"depth":1248,"text":288},{"id":784,"depth":1243,"text":785},{"id":1074,"depth":1243,"text":1075},{"id":1137,"depth":1243,"text":1138},{"id":1219,"depth":1243,"text":1220},"Produce a CSV audit report, a CycloneDX or SPDX SBOM, and graph exports.","md",null,{},{"icon":72,"group":73},{"title":69,"description":1256},"8KjEcrB3goQdxVeMmWKfFI774yqyjCmi90lNIt6psY0",[1264,1266],{"title":64,"path":65,"stem":66,"description":1265,"icon":67,"group":52,"children":-1},"Provision a whole portfolio of CI upload projects in one API request, and get back the name to UUID mapping your pipelines need.",{"title":75,"path":76,"stem":77,"description":1267,"icon":78,"group":79,"children":-1},"Understand where your projects live, why the plan belongs to the organization, and how private slots are bought and freed.",1787263157620]