Browse this SBOM
Only data present in this document is shown.
Supply Chain
-
via
Narrow to one package and everything it pulls in, which is the unit a compatibility check is really about.
This is not legal advice.
Compatibility depends on many factors your SBOM may not capture, or may get wrong. Only a lawyer can make that call.
LicenseRef- licenses are never among them.
Every element this scope reaches declares NoAssertion, so there is no license to check. Some SBOMs record licenses on a separate tree of source packages that the build tree does not link to; the licenses are in the document, just not reachable from here.
Element counts overlap: one package often declares several licenses, so the four figures above do not sum to the number of elements.
Better outbound licenses
These conflict with less of what is in scope. Pick one to re-run the check.
No license in the matrix clears everything in scope. That is the normal answer for a whole OS image, where packages ship alongside each other rather than as one combined work. Narrow the scope to a single package to ask a sharper question.
Coverage
Nothing can be checked for them, so the verdict above covers only the elements that do carry one. That is a completeness gap in the SBOM rather than a compatibility problem.
LicenseRef- licenses cannot be plotted.
Reading the grid
A row is the license of the combined work, a column the license of a component going into it. The relation runs one way, so the two halves differ.
Hover a cell to see what it means.
Compatibility rules from the OSADL Open Source License Checklists, dated , covering 119 licenses. A project by the Open Source Automation Development Lab (OSADL) eG, copyright 2017 to OSADL eG and contributors, licensed CC-BY-4.0. Informational only, not legal advice.
NVD options · bundled index · live lookup
- in
Files are matched to this SBOM by path from the CVE record, not declared by the SBOM itself. A file tagged “Not affected” or “Fixed” is cleared by a VEX statement: it's linked here for reference, not as an open issue.
Full Compile Command
No build configurations found
Try a different search or load an SPDX file with build info
Build
Raw value
Build Steps
Raw value
Build Tools
Generated Artifacts
People, organizations, and software agents referenced across the document — and everything they created, supplied, originated, or manufactured.
This file is too large to display inline ().
Statistics
Quality, structure, and relationship signals for this SBOM.
SBOM Quality Score
A completeness score across this document's packages, weighted over five categories based on the NTIA "minimum elements" baseline. It is not a security or license-compliance measure; see the breakdown below for what to fix first.
Relationship Repartition
Graph-visible relationship edges by type. Switch scope to isolate lifecycle layers.
NTIA Minimum Elements
CISA 2026 Minimum Elements
Data fields from the 2026 SBOM baseline. Signature is advisory; SBOM Version is N/A for SPDX 3.
Category Breakdown
Categories with nothing to measure in this document (e.g. no files) are excluded and the remaining weights are renormalized.
License Family Exposure
Best-effort classification by license id — a heuristic, not legal advice.
Supply-Chain Concentration
Packages the most other packages depend on — the highest-impact links if compromised.
External Reference Resolution
Elements this document references but doesn't define (SPDX ExternalMap imports).
Vulnerability Triage
How much of this document's known vulnerabilities have a resolved VEX status.
Remediation
Triage concrete SBOM data gaps and open risk findings.
The loaded SBOM does not currently produce actionable remediation findings.
Impact
Pick one element to trace why it is present and what would be affected by a change.
Find an element
Search packages, files, and other dependency-graph nodes.
Highest reach
transitive dependentsVulnerable × blast radius
CVSS presentWhy it is here
This is a document root. Nothing else pulls it in.
No dependency or containment path from a document root reaches this element.
What depends on it
Nothing depends on this element in the dependency graph.