Published 2026-09-05

From SBOM finding to product decision

Follow a release SBOM through vulnerability coverage, impact assessment, review and portable evidence.

Start with the product questions

A vulnerability list leaves a product team with several questions. Which supported releases contain the component? What evidence supports the match? Does the vulnerable functionality affect the shipped configuration? What needs to change, and who reviews that decision?

Preserve the exact release

Start with the exact release. Preserve the supplied SBOM and its origin. A component name alone may be ambiguous: an assembly name can differ from its package name, and a vendor hint is not the same as a verified package identity.

Make coverage visible

Next, separate findings from coverage. A result of zero matched vulnerabilities is meaningful only alongside what the sources could check. Unresolved components, unsupported identifiers and unavailable sources should remain visible. They are work to investigate, not evidence that the release is secure.

Assess product impact

For each supported match, record the affected package/version and the intelligence source. Show a known fixed version when one is available. Then assess the product: configuration, reachability, exposure and the available evidence can affect the decision. Preserve the rationale instead of turning an automated match into an automatic product conclusion.

Assign response and review

The response record should connect that assessment to an owner, a planned fix or mitigation, the target release and review. A future reader should be able to distinguish imported source facts from the manufacturer's judgement, including earlier decisions that were corrected.

Explore the workflow

Conformesh connects these steps around a product release. Its public walkthrough uses explicitly synthetic gateway data to illustrate inventory, coverage, a finding, a decision and the shape of an evidence record. It is an example of the workflow, not a customer result or a live advisory about the example package.

European Commission: Cyber Resilience Act · ENISA: Single Reporting Platform FAQ (checked 5 September 2026)

Explore the worked example · Check CRA readiness