Scanning an SBOM with upload scanning
SBOM file names must be in one of the following formats:
- CycloneDX (CDX) format with file name ending in
- Software Package Data Exchange (SPDX) format with file name ending in
- CycloneDX (CDX) format with file name ending in
Supported SBOM versions:
Scanning an SBOM with an application
The SCA upload scan process automatically includes SBOM results alongside those generated from uploaded lock files.
Scanning SBOM files only
To perform an SBOM-only scan, include a binary file that Veracode Static Analysis can scan alongside your SBOM files. This is necessary due to the tight integration between SCA upload scanning and static scanning.
An SBOM-only scan cannot be executed without including a scannable binary file.