CRA SBOM evidence
Meshanics stores CycloneDX or SPDX JSON against an immutable artifact version. A build-produced SBOM is preferred because it describes the exact build inputs. When a container has no attached SBOM, the Compliance and Evidence module can generate one from the pinned image and remove the pulled image after scanning.
The artifact digest, SBOM identity, scan time, package ecosystem and resulting findings remain connected to the signed release and the devices that report that artifact version. Coverage shows missing SBOMs as a gap rather than an all-clear.
An SBOM is an inventory, not proof of vulnerability, reachability or exploitability. Product-scoped review records applicability, reachability, VEX, upstream coordination, fix sharing, advisory, notification and test decisions.
See SBOM and vulnerabilities for formats, generation and triage, and Evidence and reports for issued exports.