Skip to main content

Upload and analyze an SBOM file

When you upload an SBOM file to the Threat detection page, DigiCert​​®​​ will:

  • Analyze the information from a previous threat detection scan

  • Display findings in DigiCert ONE

After the analysis is complete, critical data will display in the Threat detection details page. This information helps you to better understand your organization’s security posture, including the criticality of any detected vulnerability.

Before you begin

To upload an SBOM file and initiate a threat detection analysis, you must:

  • Ensure the file meets the following requirements:

    • Supported file format: json

    • Supported file size: Up to 50MB

  • Assign the SBOM to a project

  • Assign the file to a release (optional)

Upload an SBOM file and initiate a threat detection analysis

  1. In the Software Trust menu, go to Threat detection > Threat detection.

  2. Select Upload SMOB.

  3. Drag and drop a file or upload a file using the windows explorer.

    • You can upload multiple files.

    • When you upload a file, the Your files table displays the newly added files.

  4. Select Save and continue to manage and configure these files.

  5. Complete the missing fields:

    1. For Scan alias, enter a descriptive name for the scan.

    2. For Version, enter your own versioning system.

    3. Select an existing project or select Don't have a project? to create a new project. To learn how to create a project, see Create a project.

      1. Every uploaded SBOM file must be assigned to a project; however, it's optional to also assign a release.

      2. Once you assign an SBOM file to a project, you can;t change the project.

    4. (Optional) Select an existing release or select Don't have a release? to create a new release. To learn how to create a release, see リリースを作成する.

      1. When you select a project, the list of releases filters to only display releases that are related to the selected project and contain a detect or detect and sign purpose.

      2. You can only assign one scan per project to a release.

  6. Select Save and continue.

    1. DigiCert ONE will begin to analyze your uploaded file.

    2. To track the analysis, in the Threat detection listing page, review the Status column. A Fail or Pass value for Status indicates that the analysis is complete, and you can view the scan details.

  7. Select Close.

  8. To track the analysis, in the Threat detection listing page, review the Status column. A Fail or Pass value for Status indicates that the analysis is complete, and you can view the scan details.