Skip to main content

Dashboard Tour

The dashboard is the primary surface for a reviewer. It answers, in reading order: can I trust this SBOM, what is the risk, what exactly must I do, and what changed?

Regions​

RegionContentQuestion it answers
HeaderProduct name, SBOM document identity, export and compare actionsWhich document am I looking at?
LandingDrag-and-drop zone, demo buttonsWhere do I start?
Diff cardBaseline → current delta with a verdict badgeWhat changed?
KPI stripScore, critical, high, blockers, tainted, qualityHow bad is it, in ten seconds?
License distributionHorizontal bars coloured by tierWhat is it made of?
SBOM quality12 NTIA/audit checksCan I trust this SBOM?
Dependency graphForce-directed, risk-coloured, clickableWhat reaches what?
FindingsSeverity, rule, evidence, obligation, actionWhat do I do about it?
InventorySearchable component tableWhere is component X?
Detail panelFull component context including taint sourcesWhy did this fire?

Colour language​

The dashboard uses one consistent palette (dark theme):

ElementMeaning
Red nodeCRITICAL tier
Orange nodeHIGH tier
Yellow nodeMEDIUM tier
Green nodeLOW tier
Grey nodeUNKNOWN tier
Red edgeStatic link
Blue edgeDynamic link
Dashed edgeBuild / dev dependency
Ring around a nodeTainted — transitively reachable from copyleft

Node radius scales with degree, so hubs are visually obvious. Rendering is capped at 600 nodes; roots, high-risk and high-degree nodes are kept and the hidden count is reported.

Reading the dependency graph​

The graph is what makes the supplier conversation short. A reviewer can point at a red node, follow the red edges up to the root, and say this is the path that puts copyleft into the shipped artefact — without reading JSON.

Interactions:

  • Pan by dragging the background, zoom with the wheel.
  • Drag a node to pull its neighbourhood into place.
  • Hover a node to highlight its neighbourhood.
  • Click a node to open the detail panel.

The layout is a hand-written force simulation. It stops animating once the layout settles, and wakes on interaction — so an idle dashboard does not burn CPU.

The findings table​

This is the deliverable. Each row carries:

FieldMeaning
SeverityCRITICAL / HIGH / MEDIUM / LOW
RuleLIC-001 … LIC-009 — see the finding catalogue
ComponentThe component the finding is about
DetailThe evidence, including the dependency path
ObligationWhat the license actually requires you to do
ActionThe recommended next step

Filter by severity, search by text, and export as JSON or CSV.

:::caution Filtering never changes a verdict analyze() runs exactly once per loaded SBOM. Filtering, sorting and searching only re-render views — they cannot change a result. This is deliberate: a reviewer cannot accidentally alter an answer by interacting with the UI. :::

The component detail panel​

Clicking a component shows everything known about it:

  • Effective license and, importantly, which SPDX field it came from (licenseConcluded, licenseDeclared or licenseInfoFromFiles). A verdict derived from licenseInfoFromFiles is weaker evidence than one derived from licenseConcluded, and the panel says so.
  • Obligations derived from the license.
  • Dependencies and dependents.
  • Taint sources — which copyleft component reaches this one, at what hop distance and over what linkage.

Milestone comparison​

Load a baseline SBOM and the diff card appears. It reports:

  • Added and removed components.
  • Version bumps.
  • License changes, flagged as escalations when the tier worsens.
  • Newly introduced copyleft.
  • Regressions back to NOASSERTION.
  • New and closed findings with severity counts.
  • Risk-score and quality deltas.

On the bundled demo pair (4.1.0 → 4.2.0) it correctly reports: an AGPL MQTT client added, gpsd removed, OpenSSL relicensed (OpenSSL → Apache-2.0), legacy-codec regressed to NOASSERTION, and 2 new critical findings (risk +3).

Exports​

The dashboard can download findings and inventory as JSON or CSV. For formal artefacts — the compliance report, the NOTICE file and the supplier inquiry letter — use the CLI.