Dashboard Tour
The dashboard is the primary surface for a reviewer. It answers, in reading order: can I trust this SBOM, what is the risk, what exactly must I do, and what changed?
Regions
| Region | Content | Question it answers |
|---|---|---|
| Header | Product name, SBOM document identity, export and compare actions | Which document am I looking at? |
| Landing | Drag-and-drop zone, demo buttons | Where do I start? |
| Diff card | Baseline → current delta with a verdict badge | What changed? |
| KPI strip | Score, critical, high, blockers, tainted, quality | How bad is it, in ten seconds? |
| License distribution | Horizontal bars coloured by tier | What is it made of? |
| SBOM quality | 12 NTIA/audit checks | Can I trust this SBOM? |
| Dependency graph | Force-directed, risk-coloured, clickable | What reaches what? |
| Findings | Severity, rule, evidence, obligation, action | What do I do about it? |
| Inventory | Searchable component table | Where is component X? |
| Detail panel | Full component context including taint sources | Why did this fire? |
Colour language
The dashboard uses one consistent palette (dark theme):
| Element | Meaning |
|---|---|
| Red node | CRITICAL tier |
| Orange node | HIGH tier |
| Yellow node | MEDIUM tier |
| Green node | LOW tier |
| Grey node | UNKNOWN tier |
| Red edge | Static link |
| Blue edge | Dynamic link |
| Dashed edge | Build / dev dependency |
| Ring around a node | Tainted — transitively reachable from copyleft |
Node radius scales with degree, so hubs are visually obvious. Rendering is capped at 600 nodes; roots, high-risk and high-degree nodes are kept and the hidden count is reported.
Reading the dependency graph
The graph is what makes the supplier conversation short. A reviewer can point at a red node, follow the red edges up to the root, and say this is the path that puts copyleft into the shipped artefact — without reading JSON.
Interactions:
- Pan by dragging the background, zoom with the wheel.
- Drag a node to pull its neighbourhood into place.
- Hover a node to highlight its neighbourhood.
- Click a node to open the detail panel.
The layout is a hand-written force simulation. It stops animating once the layout settles, and wakes on interaction — so an idle dashboard does not burn CPU.
The findings table
This is the deliverable. Each row carries:
| Field | Meaning |
|---|---|
| Severity | CRITICAL / HIGH / MEDIUM / LOW |
| Rule | LIC-001 … LIC-009 — see the finding catalogue |
| Component | The component the finding is about |
| Detail | The evidence, including the dependency path |
| Obligation | What the license actually requires you to do |
| Action | The recommended next step |
Filter by severity, search by text, and export as JSON or CSV.
:::caution Filtering never changes a verdict
analyze() runs exactly once per loaded SBOM. Filtering, sorting and searching only re-render
views — they cannot change a result. This is deliberate: a reviewer cannot accidentally alter an
answer by interacting with the UI.
:::
The component detail panel
Clicking a component shows everything known about it:
- Effective license and, importantly, which SPDX field it came from
(
licenseConcluded,licenseDeclaredorlicenseInfoFromFiles). A verdict derived fromlicenseInfoFromFilesis weaker evidence than one derived fromlicenseConcluded, and the panel says so. - Obligations derived from the license.
- Dependencies and dependents.
- Taint sources — which copyleft component reaches this one, at what hop distance and over what linkage.
Milestone comparison
Load a baseline SBOM and the diff card appears. It reports:
- Added and removed components.
- Version bumps.
- License changes, flagged as escalations when the tier worsens.
- Newly introduced copyleft.
- Regressions back to
NOASSERTION. - New and closed findings with severity counts.
- Risk-score and quality deltas.
On the bundled demo pair (4.1.0 → 4.2.0) it correctly reports: an AGPL MQTT client added,
gpsd removed, OpenSSL relicensed (OpenSSL → Apache-2.0), legacy-codec
regressed to NOASSERTION, and 2 new critical findings (risk +3).
Exports
The dashboard can download findings and inventory as JSON or CSV. For formal artefacts — the compliance report, the NOTICE file and the supplier inquiry letter — use the CLI.