Skip to main content
Root home page
Search...
⌘K
Ask AI
root.io
Contact Us
Contact Us
Search...
Navigation
Reports & Insights
SBOM Reports
Getting Started
Welcome to Root
Quick Start
How Root Works
Authentication & Access
Root Image Catalog
Root Image Catalog Overview
Getting Started with RIC
Supported Images
Pulling Images
Root Patches for Images
Root Library Catalog
Root Library Catalog Overview
Getting Started with RLC
Root Patcher CLI
Python — pip, uv, Poetry
JavaScript — npm, pnpm, yarn
Java — Maven, Gradle
Root Patches for Packages
Core Concepts
Agentic Vulnerability Remediation (AVR)
Root Patches
Root Patches & Patch Stream
Vulnerability Statuses
Vulnerability Lifecycle
SBOMs
VEX Statements
Provenance
Registry Integrations
Registry Integrations Overview
Docker
Kubernetes
Amazon ECR Pull-Through Cache
JFrog Artifactory
pip
uv
Poetry
npm
pnpm
yarn
Maven
Gradle
Reports & Insights
Reports & Insights Overview
Vulnerability Reports
SBOM Reports
VEX Reports
Dashboard & Metrics
Reference
FAQ
API Reference
CLI Reference
Configuration Reference
Glossary
Changelog
Trust & Compliance
Trust & Compliance Overview
Security Posture
Certifications & Attestations
Trust Center
On this page
SBOM Report Types
Accessing SBOMs
SBOM Formats
Continuous SBOM Updates
Integrating SBOMs with External Tools
Reports & Insights
SBOM Reports
Accessing and exporting SBOMs for every image and package managed by Root.
Root maintains a current SBOM for every artifact in its registries. SBOMs are updated automatically when Root Patches are applied and are available for download at any time.
SBOM Report Types
[Per-image SBOM, per-package SBOM, fleet-wide SBOM rollup coming soon]
Accessing SBOMs
[Root platform UI, Root API endpoints, OCI annotations on images (cosign / ORAS) coming soon]
SBOM Formats
[SPDX 2.3, CycloneDX 1.5 — which fields are populated, Root-specific extensions coming soon]
Continuous SBOM Updates
[How SBOMs are versioned, how to detect changes between versions, SBOM diff endpoint coming soon]
Integrating SBOMs with External Tools
[Grype, Trivy, Dependency-Track, Anchore — how to ingest Root SBOMs coming soon]
Vulnerability Reports
VEX Reports
⌘I
Assistant
Responses are generated using AI and may contain mistakes.