
Product Announcements — shinksmon (Veracode, Inc.) asked a question.
The new SBOM API provides an inventory of components within your application with insight into the relationships between the components. Exported in CycloneDX format, the SBOM identifies which components are coming from 3rd party sources and offers visibility into your software supply chain. Check out how to do this in this quick demo.
.png)
Thanks for this.
​
After some testing, I noticed that traditional upload scans (not using SourceClear) are not supported. I think that there's a "documentation bug" because the wording "Upload Scans" (in the SBOM sections) are overloading the definition used before -- i.e. we used to call "Upload Scans" the traditional static scans that require uploading of packaged apps and we call "Agent-based Scans" the SourceClear stuff (even if they're uploaded to the Veracode Platform).
​
Also, we'd need SPDX for this feature to be usable at my Org. So I submitted this feature request: https://community.veracode.com/s/idea/0873n000000Li2GAAS/detail. Don't hesitate to vote for it. 🙂
You may already be aware, but the SBOM API now supports upload scans as well as SCA agent-based scans.