Skip to main content

SBOM Quality Checks

A verdict is only as good as the SBOM behind it. Before any risk is computed, OCSA runs 12 checks — the 7 NTIA minimum elements plus 5 additional audit elements — and reports a single quality percentage.

The demo 4.2.0 SBOM scores 50 % (6 of 12), which is representative: real supplier SBOMs routinely fail the purl, checksum and linkage checks.

NTIA minimum elements​

IDCheckPasses when
NTIA-1Supplier nameNo component is missing a supplier, or has NOASSERTION
NTIA-2Component nameEvery component has a name
NTIA-3Version identifierNo component is missing a version
NTIA-4Unique identifier (purl)Every component has a package URL
NTIA-5Dependency relationshipAt least one relationship is recorded
NTIA-6SBOM authorcreationInfo.creators is non-empty
NTIA-7TimestampcreationInfo.created is present

Additional audit elements​

IDCheckPasses whenWhy it matters
AUD-1ChecksumsEvery component has a checksumProves you analysed the artefact you shipped
AUD-2Download locationEvery component has a resolved download locationNeeded for source retrieval and offers
AUD-3Copyright textEvery component has copyright text (not NOASSERTION)Feeds the NOTICE file and LIC-008
AUD-4Files analysedNo component is marked filesAnalyzed: falseWithout it, per-file license divergence is invisible
AUD-5Linkage declaredAt least one explicit STATIC_LINK / DYNAMIC_LINK relation existsCritical for LGPL assessment

AUD-5 deserves emphasis. The LGPL verdict depends entirely on linkage. If the SBOM declares only DEPENDS_ON, OCSA assumes static linkage — the safe direction, but it over-reports. Every such finding says "linkage not declared", so a supplier can fix the SBOM and the finding goes away.

How the score is computed​

score = round((passed / 12) * 100)

It is a simple ratio of passed checks, not a weighted model. A single missing element is enough to fail a check — which is deliberate: these are minimum elements, not nice-to-haves.

What to do with a low score​

A low quality score is not itself a compliance risk — it is a data risk. It means some verdicts rest on weaker evidence. The right response is to send the supplier requirements back to the supplier and re-run, not to argue about the findings.

Use --min-quality in the release gate to reject an SBOM at intake when it is too incomplete to assess:

node tools/cli.mjs gate sbom.json --min-quality 70

Where it appears​

  • The SBOM quality panel in the dashboard lists all 12 checks with pass/fail and a count of affected components.
  • The KPI strip shows the percentage.
  • The per-ECU compliance report records it, so the review board can see that a verdict was reached on incomplete data.