このコンテンツは選択した言語では利用できません。
Chapter 2. Scanning a software bill of materials file
You can scan software bill of materials (SBOM) documents using the Red Hat Trusted Profile Analyzer service on Hybrid Cloud Console or your own {acronym} instance. The Trusted Profile Analyzer service can analyze a standard SBOM, Artificial Intelligence Bill of Materials (AIBOM) containing language models, and Cryptographic Bill of Materials (CBOM) containing keys, certificates, and libraries.
Red Hat does not retain a copy of your scanned SBOM documents.
Prerequisites
- A Red Hat user account to access the Red Hat Hybrid Cloud Console.
- An existing CycloneDX 1.3, 1.4, 1.5, 1.6 or Software Package Data Exchange (SPDX) 2.2, 2.3 document files.
Procedure
- Open a web browser.
- Go to the Application Services home page on the Hybrid Cloud Console.
- If prompted, log in to the Hybrid Cloud Console with your credentials.
- On the navigation menu, click Trusted Profile Analyzer.
- A new web browser window opens to the Trusted Profile Analyzer console home page.
- Click SBOMs from the navigation menu.
- Click the Generate vulnerability report button.
- You can drag and drop your SBOM file directly to this page, or click the Browse Files button, then choose the SBOM file you want to scan.
- After {acronym} scans the SBOM file, you get a summary of the analysis, and any specific vulnerability information for the packages included in your SBOM file.