# About Lineaje

### What is Lineaje?

Lineaje is a leading security solution to protect organizations from software supply chain attacks. Lineaje solves critical Software Supply Chain security problems faced by every organization that builds, uses or sells software. It is well-known that organizations that build, use, and/or sell software are constantly at risk for security compromises. We at Lineaje aim to keep our users aware and protected from those potential threats.

### Who needs Lineaje?

* Chief Information Security Officer who wants to secure all the software that an organization uses - build, buy, sell, use.
* Chief Product Security Officer who wants to make sure all compliance standards are met in the software supply chain.
* Open-Source Office Manager who wants to assess risk of all open-source components used.
* Software Procurement Officer who wants to assess SBOMs all third-party software components.
* Software developer who wants to assess every component in a shippable software package.


# Lineaje Product Offering

Products offered by Lineaje

## SBOM360

SBOM360 provides continuous software supply chain security management to companies by mapping out the lineage of their programs. SBOM360 is an advanced solution that helps companies protect themselves from software supply chain attacks. Through SBOM360, anyone can prepare a Software Bill of Materials (SBOM) to keep themselves and their stakeholders safe.

Here are things that you can use SBOM360 for:

* Generate SBOM for your source repo or container image or an already existing SBOM file
* View overall risk score of your SBOM
* View transitive dependencies of your SBOM
* View vulnerabilities of your SBOM
* View licenses and suppliers of your SBOM
* View inherent risk for each component based on security posture, code quality
* Download assessment report of your SBOM
* Publish your SBOM to SBOM360 Hub
* Create policies and programs as per the organizational needs
* Evaluate SBOMs against programs and generate findings

## SBOM360 Hub

SBOM360 Hub is a platform to exchange SBOMs. SBOM360 Hub enables your organization to share your private SBOMs with your customers/distributors/resellers and request SBOMs from other suppliers.

SBOM360 Hub maintains an immutable copy of the SBOM. This enables all your customers to see the same data for your products/SKU irrespective of how many times its shared.

Here are things that you can use SBOM360 Hub for

* Upload an existing SBOM generated by any SCA tool
* Verify whether your SBOM is EO14028 compliant
* Share SBOM with your customers, distributors, resellers
* Request an SBOM from a supplier
* Assess the externally uploaded SBOM in SBOM360 and view you SBOM
* Download assessment report for your SBOM

## UnifAI

UnifAI is the unified AI security orchestrator for agentic AI application development. It automatically secures AI applications as they are built and applies corporate security policies in real time. UnifAI provides continuous discovery of AI assets and enables developers to create secure AI applications by incorporating controls into agentic application development.

This gives security teams confidence that controls are consistently enforced while allowing developers to focus on speed and innovation.

To learn more, see [UnifAI](/unifai).


# Lineaje

Lineaje helps teams build trusted software, govern AI systems, and prove continuous compliance. Click to explore Lineaje's products:

<table data-view="cards"><thead><tr><th></th><th data-hidden></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>Verified open-source packages and images, rebuilt to remove exploitable vulnerabilities.</td><td></td><td data-object-fit="contain"><a href="/files/3L19JrN0fRJriSGzvVoL">/files/3L19JrN0fRJriSGzvVoL</a></td><td><a href="/pages/Vj0JCmRjdBhfHUHkhzkX">/pages/Vj0JCmRjdBhfHUHkhzkX</a></td></tr><tr><td>Automated remediation that scans, fixes, verifies, and delivers secure pull requests.</td><td></td><td data-object-fit="contain"><a href="/files/JxbWUGxAX998LlLy8dKG">/files/JxbWUGxAX998LlLy8dKG</a></td><td><a href="/pages/c343ff1fa0f8645ac1733f7b52d3d1952d36b8f1">/pages/c343ff1fa0f8645ac1733f7b52d3d1952d36b8f1</a></td></tr><tr><td>Continuous security and governance for agentic AI applications, assets, and policies.</td><td></td><td data-object-fit="contain"><a href="/files/NlLmOul69fi9s6JGwDwE">/files/NlLmOul69fi9s6JGwDwE</a></td><td><a href="/pages/eAOW8zZzlEeQkV8pqOlO">/pages/eAOW8zZzlEeQkV8pqOlO</a></td></tr><tr><td>Maps software dependencies, vulnerabilities, and risk across your supply chain.</td><td></td><td data-object-fit="contain"><a href="/files/wfrUzB1De8da6zfFEbb0">/files/wfrUzB1De8da6zfFEbb0</a></td><td><a href="/pages/VBe3V0JXHy0duyXsxAU7">/pages/VBe3V0JXHy0duyXsxAU7</a></td></tr></tbody></table>


# Getting started

The first step in getting started with Lineaje is to create an account. The first login will show the onboarding workflow which will guide the next set of steps.

The onboarding workflow takes the user through different steps like create organization, setup gates, setup integrations. The onboarding flow is built in a way where it can guide a simple setup with a default organization, a default set of gates, default set if policies. It also can guide a complete set up with a tree of organizations, custom gates, custom policies.

[Create an account](/getting-started/create-an-account)

[Onboarding workflow](/getting-started/onboarding-workflow)

<br>


# Create an account

There are 3 different ways to create an account in Lineaje. The signup page can be found here - <https://app.veedna.com/auth/signup>

1. Create an account based on corporate email
2. Create an account based on your existing accounts (GitHub, Gitlab, Bitbucket)
3. Enable sso (single sign on) with your corporate account

### 1. Create an account based on your corporate email

You can create an account in Lineaje using your corporate email account.&#x20;

* Go to <https://app.veedna.com/auth/signup>
* Click on "Signup with email"
* Add your email address, first and last name, and create a password
* A verification email will be sent to the provided email address
* Upon verification of the email address, the user will be allowed to sign-in

<figure><img src="/files/dDj8yY9AHy9B9VYuqCGE" alt=""><figcaption></figcaption></figure>

If you are not the first user from your organization trying to sign-up, then the Tenant Admin for your org should assign a role for you to login. Please read below to learn more.

#### **Tenant Admin and regular users**

The first individual to sign-up with Lineaje will automatically be instated as the admin for your organization. The Tenant Admin will have the permissions to add other users and assign roles for users from the same organization. Learn more about [user management](/getting-started/organization-and-user-management).

The subsequent users who sign-up will be created but a role will not be assigned. As a result the user may see an error message “Request Permission”. The Tenant Admin must login and assign a role to users to complete the sign-up.

<figure><img src="/files/8T8igVS017FdZuNlQpti" alt=""><figcaption></figcaption></figure>

#### **User Approval**

The approval process requires the Tenant admin to:

* Go to Settings
* Open "User Management"
* Open "Users" tab
* Select the pending user (user without any role, any organization)
* Assign the user an SBOM360 role
* Assign the organization

<figure><img src="/files/a2P7jwhh1i4xf8gtXsyk" alt=""><figcaption></figcaption></figure>

### **2. Create an account based on your existing accounts (GitHub, Gitlab, Bitbucket)**

You can create an account based on your existing GitHub, GitLab, Bitbucket.&#x20;

* Go to <https://app.veedna.com/auth/signin>
* Add your existing credentials with GitHub/GitLab/Bitbucket
* A pop up would appear to give access to your account
* Upon giving access, the account creation will succeed

<figure><img src="/files/KRdLU3swOogfpLGTMPWu" alt=""><figcaption></figcaption></figure>

On first login, you will become the tenant admin for the new tenant that gets created. If you want to add other users to your tenant, you will have to invite them. Follow the steps below:

* Go to Settings
* Open "User Management"
* Open "Users"
* Click on "Invite user"

The new user gets an email invitation with a link to login using existing credentials (GitHub, GitLab, Bitbucket)

### **3. Enable sso (single sign on) on your corporate account**

You can enable sso using saml. There are two steps to enable sso.&#x20;

**Step 1: Create a new account using corporate email**

* Create a new account using the[ corporate email](#id-1.-create-an-account-based-on-your-corporate-email).
* This account becomes the tenant admin.

**Step 2: Enable sso with saml**

* [Login ](https://app.veedna.com/auth/signin)using the newly created account
* Goto Setting -> Authentication -> Edit Configuration -> Click on Single Sign On
* Enter the Sign-in url
* Upload the SAML .cer file
* Click on Enable sso.

<figure><img src="/files/EaCbN7CaPI15o0VpdfLq" alt=""><figcaption></figcaption></figure>

Refer [Azure AD sample](/getting-started/create-an-account/configure-azure-ad-for-sso), [Okta sample](/getting-started/create-an-account/configure-okta-for-sso)

#### Support for Service Provider Initiated and IDP-initiated sso

There are two types of sso workflows.&#x20;

In Service Provider-initiated sso, a service provider (in this case Lineaje app) requests authentication from an identity provider to validate an authenticated user’s access to an application.

In IDP-initiated sso,  an identity-as-a-service provider (IdP) is used to validate an authenticated user’s access to an application. There are known security risk associated with IDP-initiated sso. So its disabled by default. If you organization needs this, please contact Lineaje at <support@lineaje.com>.


# Configure Azure AD for sso

Sample configuration for Azure AD to enable sso

### Create an application

* Go to [Azure portal](https://portal.azure.com/) and navigate to [Azure Active Directory](https://portal.azure.com/#view/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/~/Overview)
* Click on the Enterprise Application item on the left-hand side navigation pane.
* Under the Enterprise application section, create a new application by clicking the ‘+ New Application’ button on the top menu bar.
* Then, click on the ‘Create your Own application’ button on the top menu bar.
* Provide a name to your application and make sure to choose the ‘Non-Gallery’ application mode.

<figure><img src="/files/2MlDVEbzo46ExEx1h3vv" alt=""><figcaption></figcaption></figure>

* Click on create.
* Once the application has been created, click on the ‘Single sign-on’ option on the left-hand side navigation pane.
* By default, SSO feature is disabled. Since we need to proceed with SAML based login, click on the SAML widget. Then you would be directed to SAML configurations.
* Fill the following values into their respective SAML configurations in the Azure AD.

```
Identifier (Entity ID) -> Entity ID which you have generated in above step in the Lineaje Application

Reply URL (Assertion Consumer Service URL) -> Post callback URL which you have generated in above case.
```

### Configure SAML

<figure><img src="/files/3hgNKL5ABQDuExCT8dXx" alt="" width="563"><figcaption></figcaption></figure>

* Once above configurations are done, click on the ‘Users and Group’ section on the left-hand side navigation pane to allow users who can use above configured SAML configurations to login to their target platform.

<figure><img src="/files/xK6MtbZQ1N4wLq48fhSS" alt=""><figcaption></figcaption></figure>

* Click on the ‘None Selected’ and select ‘All Users’ to allow every available user in the AD to allow access to the application. Alternatively, you can choose individual users to allow access.

<figure><img src="/files/FbfY5lKQFjoT3P3xDCxq" alt=""><figcaption></figcaption></figure>

Go Back to ‘Single sign-on’ from left-hand navigation menu and click on the ‘Test’ button to test your SAML configurations.

With the Auth0 configuration which we have done so far, if you were able to get following response in the web browser which means your Azure side configurations are working in a proper way.&#x20;

***Copy the URL in the browser and have it handy. This will be required in the next step.***

<figure><img src="/files/hRMBX5elCprzhsX2KCVi" alt=""><figcaption></figcaption></figure>

### Configure Lineaje Application with SAML details

* Copy the SAML certificate
* Copy the Login URL

<figure><img src="/files/mTkbOvL6ldPpoU22u7Ry" alt=""><figcaption></figcaption></figure>

* [Login ](https://app.veedna.com/signin)to Lineaje application.
* Goto Setting -> Authentication -> Edit Configuration -> Click on Single Sign On
* Enter the Sign-in url with the LoginURL

<figure><img src="/files/5dzXlG9ZmvE6m00fNrRa" alt=""><figcaption></figcaption></figure>

* Upload the SAML .cer file

<figure><img src="/files/Sg0IFZRa2TfJmystJIQ4" alt=""><figcaption></figcaption></figure>

* Veirfy that the callback url is the same as the one during [SAML configuration](#configure-saml)

<figure><img src="/files/zNfzwZXqpHBtCDzCZhwA" alt=""><figcaption></figcaption></figure>

* Click on Enable sso.


# Configure Okta for sso

### Enable sso in Lineaje application

Keep the EntityID and Callback URL handy

<figure><img src="/files/V1U3wgqheS8cvBRpPqed" alt="" width="563"><figcaption></figcaption></figure>

### Create an application in Okta

* Go to Okta portal and switch to admin mode.
* From the left-hand side navigation pane, go to Applications -> Applications

<figure><img src="/files/sjLiQreGbHhiSJRgbl3a" alt="" width="563"><figcaption></figcaption></figure>

* Click on "Create APP Integration"
* Select SAML 2.0 and click next.
* Enter the app name, say "Demo-Okta-Sample"

<figure><img src="/files/qSz10KrKEjmhUTQcbxxf" alt="" width="563"><figcaption></figcaption></figure>

### Configure SAML in Okta

* Fill the following values into their respective SAML configurations.
  * *Audience URI (Entity ID)* -> Entity ID which you have generated in Lineaje application
  * *Single sign-on URL* -> Post callback URL which you have generated in Lineaje application.
  * Select the Name ID Format as "EmailAddress"

<figure><img src="/files/SvgkW8b4p2CCv44YKQ7Z" alt="" width="547"><figcaption></figcaption></figure>

* Set the Attribute Statements. These attributes will be part of SAML assertion and this is required for Lineaje auth to function.

<figure><img src="/files/OD3UPbwOfEZ4DtiZhUCa" alt="" width="563"><figcaption></figcaption></figure>

* Click on following options and click on Finish. Depending on the version of Okta, there could be slightly different screens shown. Two variations are shown below.

<figure><img src="/files/k8TN2hmB0Y8yEUnSTMiH" alt="" width="557"><figcaption></figcaption></figure>

<figure><img src="/files/LsdRkNMokVMdcq8COY1O" alt="" width="563"><figcaption></figcaption></figure>

### Assign users or groups

* Goto Assignments tab
* Assign individual users or groups to the application.

<figure><img src="/files/vmxAIZLlN7atVdOL0JtC" alt="" width="563"><figcaption></figcaption></figure>

### Follow SAML setup instructions in Okta

* Go to Sign On-> View SAML setup instructions link

<figure><img src="/files/YymXTlyrKPVwK0RsFpMC" alt="" width="563"><figcaption></figcaption></figure>

* Copy the identity provider single sign-on url, download the x.509 certificate

<figure><img src="/files/HA4qgeEtO3JoDHv89rXB" alt="" width="563"><figcaption></figcaption></figure>

### Configure the Lineaje application

* Go back to Lineaje application
* Copy the identity provider single sign-on url in "Sign-in URL"
* Upload the certificate from previous step.

<figure><img src="/files/cnvsHRkpzCd6gq59689e" alt="" width="563"><figcaption></figcaption></figure>

* Proceed with activating Single Sign On(SSO)

<figure><img src="/files/oqAaABa9njyGlj3Ix2hP" alt="" width="540"><figcaption></figcaption></figure>


# Onboarding workflow

On first login, you will be presented with an onboarding workflow. The onboarding flow is different for a Tenant Admin, Org Admin and a Function User.

### **Tenant Admin/ Org Admin onboarding workflow**&#x20;

The onboarding flow will guide you to setup child organizations (optional), setup additional gates (optional), invite users to create policies for gates, invite users to create integrations.

<figure><img src="/files/5QZBgnI8fbGKjjKtOEAu" alt=""><figcaption></figcaption></figure>

1. Global Organization

By default, a root organization will be created for you. All users will belong to this root organization. In this step, you can change the name of the root organization. You are the tenant admin and you will be the org admin for this root organization.

2. Gates

The second step is to create additional gates. As a tenant admin, you can create gates that you want your entire org to be evaluated against. For e.g., it could be a gate related to open source vulnerabilities or it could be a gate related to open source provenance or it could be a gate related to usage of specific license or it could be a gate related to usage of components from a particular vendor and so on.

Gates are inherited. So a gate that is assigned to an org will be applied to the SBOMs in that org and all of its sub orgs. You can learn about gates [Policies and Gates](/sbom360/policies-and-gates).&#x20;

The default gates are already applied and show up.&#x20;

3. Child organization

Creating child organizations is an optional step. By default all users belong to the default root organization.

You can create child organizations. Organizations may map to a team, BU, product team etc. You can create orgs and sub-orgs that can map to your company. Organization decides the visibility and ownership of SBOMs.

4. Setup integrations

The last step is to setup integrations. In this step, you can configure the tokens necessary to access the source repository, image repository. Once configured, this can be used for SBOM generation.

### Function User Workflow

The teannt Admin/Org Admin could have delegated the policy setup and/or integration setup to function users. When a function user logins for the first time, an onboarding flow will show up to guide the user on the tasks.

<figure><img src="/files/TlpU1N09mttqN943zRCq" alt=""><figcaption></figcaption></figure>

1. Your Roles

This step gives the information about the roles assigned to this function user.2

2. Your Organizations

This step gives the information about the organizations to which the fucntion user belongs to.

3. Assigned Tasks

This step lists the assigned (delegated) tasks to the user. This will list the delegated tasks - setup policy or setup integrations or both.&#x20;

* Clicking on "Create Policy" will take the user to the Policy page
* Clicking on "Setup Integration" will take the user to the Integrations page

<figure><img src="/files/XtybaGT0aCqBaM5bBaCC" alt=""><figcaption></figcaption></figure>


# Organization and User Management

Create/Modify  Organizations, Create/Modify Users

Organization and User Management is under Settings from left navigation bar.

<figure><img src="/files/t96NxLYtOCk6HNYGPzYc" alt=""><figcaption></figcaption></figure>

### Organization Management

#### What is an organization?

Organizations refer to a group of users who can create/view projects. Organization decides the visibility and ownership of projects. Organizations may map to a team, BU, product team, functional team etc. You can create orgs and sub-orgs that can map to your company.&#x20;

* Organizations are customer defined
* An organization decides the visibility of projects.
  * A user at the root of the tree can access all projects under root
  * A user at the leaf node can access projects associated with the leaf node
* Each organization can have multiple users
* Every organization MUST have an "Org Admin" who can manage that org.
* Tenant Admin and Org Admin can create or modify organizations

#### Add/Modify organization

* Goto "Settings" page on the left navigation bar
* Goto "organizations" tab
* Click on "Add Organization"

#### Add user to an organization

* Goto "Settings" page on the left navigation bar
* Goto "organizations" tab
* Click on "Add User"

### User Management

#### Function

A function defines a user role. There are different functions defined to choose from.

AppSec, DevOps, DevSecOps, GRC, Legal, Open Source Office, Product Security, Quality, Sales, SBOM Approver, Tenant Admin, Org Admin

A function to which a user belongs to will enable/disable certain functionalities. For e.g. a Tenant Admin can only add organizations, users etc.

#### Add/Modify User

1. In the left-hand navigation, go to **Settings**.
2. Click **User Management**.
3. Click **Link User** to add a new user.


# Organization example

<figure><img src="/files/xFdh93O5xzPJtq2IhpDI" alt=""><figcaption></figcaption></figure>

| **Access**                       | **RootOrg**                                                                                            | **Org1**                                                      | **Org2**                                  | **Org11**                          | **Org12**    | **Org21**    | **Org22**    |
| -------------------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------- | ----------------------------------------- | ---------------------------------- | ------------ | ------------ | ------------ |
| View Gates                       | G1, G2                                                                                                 | G1, G2                                                        | G1, G2, G3                                | G1, G2, G4                         | G1, G2       | G1, G2, G3   | G1, G2, G3   |
| View SBOMs                       | <p>SBOM-1</p><p>SBOM-2</p><p>SBOM-11(1)</p><p>SBOM-11(2)</p><p>SBOM-12</p><p>SBOM-21</p><p>SBOM-22</p> | <p>SBOM-1</p><p>SBOM-11(1)</p><p>SBOM-11(2)</p><p>SBOM-12</p> | <p>SBOM-2</p><p>SBOM-21</p><p>SBOM-22</p> | <p>SBOM-11(1)</p><p>SBOM-11(2)</p> | SBOM-12      | SBOM-21      | SBOM-22      |
| View Integrations                | None                                                                                                   | Intg-1                                                        | None                                      | None                               | None         | None         | Intg-2       |
| View Findings                    | F1 to F 30                                                                                             | F1 to F21                                                     | F22 to F30                                | F1 to F21                          | None         | None         | F22 to F30   |
| View Cases                       | C1 to C21                                                                                              | C1 to C12                                                     | C13 to C21                                | C1 to C12                          | None         | None         | C13 to C21   |
| CUD Gates                        | UO, UL, TA                                                                                             | None                                                          | U2                                        | UM                                 | None         | None         | UM           |
| CUD SBOMs (update SBOM metadata) | None                                                                                                   | U1                                                            | U2                                        | UM                                 | U12          | U21          | UM           |
| CUD Integrations                 | None                                                                                                   | U1                                                            | None                                      | None                               | None         | None         | UM           |
| CUD Findings                     | NA                                                                                                     | NA                                                            | NA                                        | NA                                 | NA           | NA           | NA           |
| CUD Cases                        | Assignee/Org                                                                                           | Assignee/Org                                                  | Assignee/Org                              | Assignee/Org                       | Assignee/Org | Assignee/Org | Assignee/Org |


# Deploying Lineaje

Lineaje supports SaaS and hybrid deployment models, so you can choose the right balance of speed, control, and network isolation for your environment.

Lineaje supports the following deployment models:

* [SaaS Deployment](/deploying-lineaje/saas-deployment)
* [Hybrid Deployment](/deploying-lineaje/hybrid-deployment)


# SaaS Deployment

In SaaS mode, you provide access tokens for your source code repositories or container registries. No software installation is required on your infrastructure.&#x20;

{% stepper %}
{% step %}

### Prerequisites

Complete the [prerequisites](/deploying-lineaje/saas-deployment/prerequisities) for deployment.
{% endstep %}

{% step %}

###

{% endstep %}
{% endstepper %}


# Prerequisities

* A [Lineaje account](/getting-started/create-an-account). Contact Lineaje Support for access.&#x20;
* Access tokens for your source code repositories ([GitHub](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens), GitLab, Bitbucket) and container registries.


# Page 2


# Integrations

### Generate an SBOM Project

The Integrations page offers several starting points for generating an SBOM project, categorized by source type: SCM, Container Registries, AI Model, and continuous Integration.

<figure><img src="/files/UAH5laHJu0kU0fTddS4U" alt=""><figcaption></figcaption></figure>

1. Log in to the [Lineaje portal](https://app.veedna.com/auth/signup).&#x20;
2. Navigate to **Integrations** > **Scan Remotely**.&#x20;
3. Select your source type (GitHub, GitLab, Bitbucket, or container registry).&#x20;
4. Click **Add Integration**. **Select your source for detailed setup steps:**
5. Provide your access token and repository URL.&#x20;
6. Click **Connect**. Lineaje scans the repository and generates a project automatically.

Select your source for detailed setup steps:

* [Source Code Management (SCM) As Source](/sbom360/generate-an-sbom/source-code-management-scm-as-source)
* [Container Image As Source](/sbom360/generate-an-sbom/container-image-as-source)
* [Existing SBOM As Source](/sbom360/generate-an-sbom/existing-sbom-as-source)
* [Manifest file As Source](/sbom360/generate-an-sbom/manifest-file-as-source)
* [Android Package Kit(APK)](/sbom360/generate-an-sbom/binary-files)


# Source Code Management (SCM) As Source

Create a configuration for SCM integration. Each configuration stores settings for a private or public code repository. A public repository configuration supports up to 10 repository URLs. A private repository configuration requires credentials with sufficient permissions to enumerate and list the repositories.


# Public Code Repositories

SBOMs can be generated for public code repositories. Following are the steps to configure a public code repository:

{% stepper %}
{% step %}

### Add Details

Add the following details:

* **Name**: Enter a name for GitHub configuration
* **Description**: Add a description for the configuration
* **Enter a public GitHub URL**: Add up to 10 public code repository URLs per configuration. Lineaje verifies each URL for accessibility and displays its status.

<figure><img src="/files/CR8G6zW6dHVx89lnhjdT" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Review and Save Configuration

1. Review the following: Repository Name, Branch, Tag, Project Name, and Version. You can also edit the auto-generated Project Name and Version.
2. Click **Save Configuration** to generate the SBOM.
   {% endstep %}
   {% endstepper %}


# Private Code Repositories

Private code configuration requires credentials to access the private code. This may include a combination of access token, username, certificates depending on the SCM platform.&#x20;

<figure><img src="/files/oTvR87VYBwbkMxQcjCNm" alt=""><figcaption></figcaption></figure>

1\. In the **Details** section:

* **Name**: Enter a name for the configuration.
* **Description**: Add a description for the configuration.
* <mark style="color:$danger;">**User Name**</mark><mark style="color:$danger;">: ?</mark>
* <mark style="color:$danger;">**Access Token**</mark><mark style="color:$danger;">: ?</mark>
* **Test Connection**: Click to test connection against the credentials.

2. Click **Next**.
3. In the **Review** section, review the following: **Repository Name**, **Branch**, **Tag**, **Project Name**, and **Version**. You can also edit the auto-generated **Project Name** and **Version**.
4. Click **Save Configuration** to generate the SBOM.

![](/files/eAPBHovwi2futPQhJA2I)


# Configure GitHub credentials

GitHub configuration requires a "Personal Access Token".

## Creating Personal Access Token

Refer [GitHub docs](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens) to create Personal Access Token.

* Go to [github.com](https://github.com/) and sign-in
* Select your profile.
* Click on Settings.
* Click on Developer Settings.
* Click on Personal access tokens.
* Enter a token name.
* Set an expiration date (optional).
* Define scopes with the following permissions:
  * Repository – contents – read
  * Repository – metadata – read
* Click on Create personal access token.
* Add the newly generated token as "Access Token" in Lineaje configuration.


# Configure Bitbucket credentials

Bitbucket configuration requires "User Name" and "Access Token".

Bitbucket supports two types of access tokens depending on the access privileges. There are two types of tokens that can be generated based on your access rights to Bitbucket.

## Creating App password

Refer [Bitbucket Docs](https://support.atlassian.com/bitbucket-cloud/docs/create-an-app-password/) to learn about creating App password.

* Go to [bitbucket.org](https://bitbucket.org/).
* Go to your repository.
* Select the Settings cog in the upper-right corner of the top navigation bar.
* Under **Personal settings**, select **Personal Bitbucket settings.**
* On the left sidebar, select App passwords.
* Select Create app password, select permissions and save.
* Set the "User Name" in Lineaje configuration to your Bitbucket username. Please note that bitbucket username may not be the same as your email id.
* Add the newly generated token as "Access Token" in Lineaje configuration.

## Creating Access Tokens

Refer [Bitbucket Docs](https://support.atlassian.com/bitbucket-cloud/docs/access-tokens/) to learn about creating Repository/Project/Workspace Access Tokens and [creating](https://support.atlassian.com/bitbucket-cloud/docs/create-a-repository-access-token/) the repository tokens.

* Go to [bitbucket.org](https://bitbucket.org/).&#x20;
* Go to your repository.
* Click Repository Settings.
* Select Access tokens.
* Press Create Repository Access Token.
* Create a token name.
* Select the repository token permissions.
* Click the Create button.
* Copy the token and save it somewhere memorable. The token will be inaccessible once you leave the page.
* As per the Bitbucket docs, set the "User Name" to "**x-token-auth**" in Lineaje configuration.
* Add the newly generated token as "Access Token" in Lineaje configuration.


# Configure Gitlab credentials

Gitlab configuration requires "User Name" and "Access Token".

## Creating Personal Access Token

Refer [Gitlab docs](https://docs.gitlab.com/ee/user/profile/personal_access_tokens.html) to create Personal Access Token.

* Go to [about.gitlab.com](https://about.gitlab.com/) and sign-in
* Select your profile.
* Click Edit profile.
* Click on Access Tokens.
* Enter a token name.
* Set an expiration date (optional).
* Define scopes.
* Click on Create personal access token.
* Set the "User Name" in Lineaje configuration.
* Add the newly generated token as "Access Token" in Lineaje configuration.


# Configure Git credentials

git configuration requires "User Name" and "Access Token". The exact steps of creating the access token depends on the git cloud that is used.

## Creating Personal Access Token

* Depending on the git cloud used, follow the instructions to generate a personal access token.
* Set the "User Name" in Lineaje configuration.
* Add the newly generated token as "Access Token" in Lineaje configuration.


# Configure Azure Repo

Azure Repo uses standard git interface. Azure Repo can be configured using "[Git](/sbom360/generate-an-sbom/source-code-management-scm-as-source/private-code-repositories/configure-git-credentials)".

* Login to your account in [dev.azure.com](https://dev.azure.com)
* Top right corner, click on User Settings
* Click on Personal Access Token
* Click on "New Token"
* Add Name, Organization, Expiration, Scopes (Read access is preferred)

<figure><img src="/files/3WkM10k2WkUaakTJseje" alt=""><figcaption></figcaption></figure>


# Container Image As Source

SBOM360 supports integration with different container registries.

* Create a configuration for container image integration. This helps the organizations to group image registries based on location or team or product.
* Each configuration can store settings for private or public image registry
* In case of [public image registry](/sbom360/generate-an-sbom/container-image-as-source/public-container-image), one configuration can store up to 10 public image URLs
* In case of [private code registry](/sbom360/generate-an-sbom/container-image-as-source/private-container-image), access must be given to enumerate and list the private container images.

<br>


# Public Container Image

SBOMs can be generated for public container images. There are two steps involved:

### Step 1: Details

* Each configuration can store up to 10 container image URLs
* Each container image URL is verified for its accessibility and a status is displayed

<figure><img src="/files/98faCftk4BE4uhDLIdPK" alt=""><figcaption></figcaption></figure>

### Step 2: Review

* The tags available for the verified conatiner image are listed in this step
* Choose a tag to generate an SBOM
* Project name and version will be auto generated but can be edited
* Click on “Save Configuration” to generate SBOM

<figure><img src="/files/NqBZDBDTyzgnkONSYUCX" alt=""><figcaption></figcaption></figure>

<br>


# Private Container Image

SBOMs can be generated for private code repositories.

There are three steps involved:

### Step 1: Details

* Each configuration requires a mandatory name and a description.

<figure><img src="/files/xk5jGnEvIiVuj6OfSAQz" alt=""><figcaption></figcaption></figure>

### Step 2: Configure

* Enter the credentials required to access the private registry. This gives Lineaje access to your organization’s private image registry,
* This step varies for AWS-ECR, GCP-Container Registry, and Docker Hub.
* By clicking on Test Connection, the connection will be tested against the credentials.

<figure><img src="/files/Izf2znNM3UrYLZI4Ujvq" alt=""><figcaption></figcaption></figure>

### Step 3: Review

* All the container images available in the private registry will be displayed
* Choose a container image
* Project name and version will be auto generated but can be edited
* Click on Save Configuration to generate a project


# Configure AWS Elastic Container Registry

Provide credentials to access private ECR

There are two options to configure access to AWS-ECR private registry: CloudFormation Template and Configure Manually

### Manual Configuration

This configuration allows you to enter the accountID, accessToken, secretkey and Region. This would allow Lineaje to get access to your organization’s private ECR registry.

For security reasons, Lineaje recommends creating new user with cross account role. Follow the below steps to create a new user:&#x20;

* Go to the AWS console and login using your organization credentials
* Navigate to Identity and Access Management (IAM) and click Users
* Add users, then enter the user name

<figure><img src="/files/HnCEonkCAQ7hnc3eTI0w" alt=""><figcaption></figcaption></figure>

* For the AWS credential type, press Access key - Programmatic access then set permissions. There are two required permissions you will need to set:
  * AmazonEC2ContainerRegistryFullAccess
  * AmazonElasticContainerRegistryPublicFullAccess

<figure><img src="/files/QLk9IYGJBTWvyhWOBhju" alt=""><figcaption></figcaption></figure>

* Skip Tags Tab
* Review Tab

<figure><img src="/files/Yj2FqgwF7jMOYGUafHVI" alt=""><figcaption></figcaption></figure>

* Final tab will provide you the access key id and secret access key

<figure><img src="/files/rrLmhiU3QfzfPRuTo7yN" alt=""><figcaption></figcaption></figure>

### IAM CloudFormation Template​

The CloudFormation Template (CFT) option needs a CFT file to be uploaded.&#x20;

* Download the sample CFT file
* Go to the AWS console and login using your organization credentials

  * Go to the AWS *sign-in page* <https://console.aws.amazon.com/cloudformation&#x20>;
  * Click the buttons Create Stack -> With New Resources

  <figure><img src="/files/iRnpJnXRfX0dibfo8vGh" alt=""><figcaption></figcaption></figure>

  * Leave the Prepare Template setting as-is
    * For Template source select Upload a template file
    * Click Choose file and select the CloudFormation template you downloaded and click Next

  <figure><img src="/files/Q82pevnIl9HoUOqvA2b2" alt=""><figcaption></figcaption></figure>

  * For Stack name use SBOM360-ECR-Permissions-Stack and click Next

  <figure><img src="/files/jB4wCOvrc1JGSKnPtbwN" alt=""><figcaption></figcaption></figure>

  * For Configure Stack Options, it is recommended to use configuring tags, which are key-value pairs that can help you identify your stacks and the resources they create. You will not have to use additional permissions or advanced options so click Next.
  * For Review

    * Scroll down to the bottom of the page and select "I acknowledge that AWS CloudFormation might create IAM resources with custom names."
    * Click Create Stack

    <figure><img src="/files/B7nrd0VSP3nGLrCwwezw" alt=""><figcaption></figcaption></figure>

    * You will be taken to the CloudFormation stack status page, showing the stack creation in progress
      * Click on the Events tab and watch the CloudFormation events as they form the IAM Role
    * Click on the Outputs tab and copy the value of the EcrIntegrationRoleARN key

    <figure><img src="/files/DHSIcSKfn0pwnmhEcQiR" alt=""><figcaption></figcaption></figure>

    * It should look similar to the following key - arn:aws:iam:/sbom360/SBOM360\_ECR\_Role
* Upload the updated CFT in the configure step
* By clicking on Test Connection, the connection will be tested against the credentials


# Configure Google Container Registry

To give access to your organizations’ artifact registry, you will have to enter the project-ID, region and upload the Google Service Account file.

\
To identify the project-ID, follow these steps:

* Go to the GCP console and login using your organization credentials
* Go to the API Console and view the projects list
* Move to the projects list and click Manage all projects
  * NOTE: The Manage all projects space will display all the project names and IDs that you are a member of.
* Navigate to the desired project select the project to display its project-ID


# Configure Docker Hub

To give access to your organizations’ Docker Hub account, you will have to provide the Docker ID and Access Token of the Docker Hub to start this process.&#x20;

<br>


# Configure Generic OCI Registry


# Configure Azure Container Registry

Azure Container Registry supports the standard Docker commands. Azure Container Registry can be configured using "[OCI Compatible Registry](/sbom360/generate-an-sbom/container-image-as-source/private-container-image/configure-generic-oci-registry)".

* Goto [portal.azure.com](https://portal.azure.com.).
* Search to Container Registry
* Navigate to your private Container Registry
* Goto Settings -> Access Keys
* Enter the details -> Registry Name, Login server, Admin user, Username, password, password2

<figure><img src="/files/n8qtFurLKFIB6Rx1vLcr" alt=""><figcaption></figcaption></figure>


# Frequently Asked Questions

### Why do I not see a new project triggered even after clicking on "Save Configuration"?

Project generation has a n optimization to avoid accidental runs of same project configuration. A combination of Project Name, Version, digest of the image is used to generate a unique identifier for each project. A project run is triggered only if the combination of Project Name and Version does not exist.

Note: If its only for testing, the previous project in projects page can be deleted to trigger a new run for the same image.

### How can I change the settings for an existing project?

To change the configure, click on edit configuration.

* Step 1 (Details): Configuration name, description, credentials, repo URLs can be modified.
* Step 2 (Review): Branch/tag can be changed for the existing configuration by going to "Edit Repositories" tab.
* Click on Save Configuration to trigger a new project.


# Existing SBOM As Source

Generate a project by uploading your existing SBOMs in either SPDX or CycloneDX format.

Follow the below steps:

1. Step 1: Project name and version
   1. Enter a name and version for your project.
2. Step 2: Choose format and upload file
   1. Choose the format of your SBOM.
      1. SBOM360 supports both SPDX and CycloneDX files.
      2. Please refer the [support matrix](/sca360-secure-deployment-for-restricted-environments/support-matrix) for  supported versions and formats
   2. Drag and drop or browse to find and enter your desired SBOM file.
   3. CSV uploads are also supported.  Please refer to the following sample file for the supported format.

{% file src="/files/Uhcd8iscswjLhh3Tu39U" %}

1. Step 3: Review
   1. For every file uploaded, [EO 14028](/sbom360/generate-an-sbom/existing-sbom-as-source/eo-14028-checks) check is performed and errors (if any) are displayed
   2. Once the submit is clicked, the SBOM generation kicks off
   3. Please note that the outcome of an SBOM generation with errors in the EO 14028 check will be incomplete.

<figure><img src="/files/x5T83QIedgUJCBRACOEL" alt=""><figcaption></figcaption></figure>


# EO 14028 checks

Minimum elements for an SBOM

### Minimum fields

EO 14028 checks correspond to the minimum elements in an SBOM as described by <https://www.ntia.doc.gov/files/ntia/publications/sbom_minimum_elements_report.pdf>

The table below lists the minimum elements. Some of these fields are at a SBOM level and the others are applicable for each component in the SBOM.

<table><thead><tr><th width="248">Data Field</th><th>Description</th></tr></thead><tbody><tr><td>SBOM Timestamp</td><td>Record of the date and time of the SBOM data creation</td></tr><tr><td>SBOM Author</td><td>The name of the entity that creates the SBOM data for this component</td></tr><tr><td>SBOM dependencies</td><td>Characterizing the relationship that a component X is included in software Y</td></tr><tr><td>Component Name</td><td>Designation assigned to a unit of software defined by the original supplier</td></tr><tr><td>Component Version</td><td>Version assigned to a unit of software defined by the original supplier</td></tr><tr><td>Component Supplier Name</td><td>The name of an entity that creates, defines, and identifies components</td></tr><tr><td>Component Unique Identifiers</td><td>Identifiers that are used to identify a component (like PURL, BomRefId etc)</td></tr></tbody></table>

### Mapping of minimum fields&#x20;

Below is a table mapping the NTIA minimum SBOM fields to SPDX and CycloneDX

|                         | SPDX                                       | CycloneDX                                                        |
| ----------------------- | ------------------------------------------ | ---------------------------------------------------------------- |
| SBOM Timestamp          | (2.9) Created:                             | metadata/timestamp                                               |
| SBOM Author             | (2.8) Creator:                             | metadata/authors/author                                          |
| SBOM dependencies       | (7.1) Relationship: DESCRIBES CONTAINS     | Inherent in nested assembly/subassembly and/or dependency graphs |
| Component Name          | (3.1) PackageName:                         | name                                                             |
| Component Version       | (3.3) PackageVersion:                      | version                                                          |
| Component Supplier Name | (3.5) PackageSupplier:                     | Supplier publisher                                               |
| Component Unique Ids    | (2.5)SPDX Document Namespace (3.2) SPDXID: | bom/serialNumber component/bom-ref                               |


# Manifest file As Source

A manifest file is a configuration file that build tools use to build a project. A manifest file typically carries various build configurations as well as information about dependencies.

Enteprises do not expose the source code. The scm tool that is used for source code management is accessible within the enterprise boundary. So the persona who wants to generate SBOM using Lineaje is often stuck with getting right permissions to provide Lineaje cloud access to the source code. To simplify the SBOM creation, Lineaje supports uploading of the manifest file alone. Doing so will kick start the SBOM generation. All private and third party dependencies referred in the manifest file will remain unresolved as Lineaje does not have access. On the other hand all open source dependencies show up.

The below table lists down the supported manifest files for different build tools. The manifest file typically is found in the root of the source code. Depending on the type of the project, there could be one or more manifest files (root + sub directories).

<table data-header-hidden><thead><tr><th width="92.33333333333331">#</th><th width="323">Build tool</th><th>Manifest file</th></tr></thead><tbody><tr><td>1</td><td>Java / Maven</td><td>pom.xml</td></tr><tr><td>2</td><td>Python / PIP</td><td>requirements.txt</td></tr><tr><td>3</td><td>Rust / Cargo</td><td>Cargo.lock</td></tr><tr><td>4</td><td>Golang / Go Modules</td><td>go.mod</td></tr><tr><td>5</td><td>Yarn</td><td>yarn.lock</td></tr><tr><td>6</td><td>JavaScript / NPM</td><td>package-lock.json</td></tr></tbody></table>


# Binary Files

You can generate an SBOM for your applications using this option.

Currently, the following binary types are supported: **Windows EXE, Windows MSI, Windows DLL, and Android APK**.

Follow the steps below:

* Enter a name and version for your project.
* Drag and drop or browse to select your desired binary file (**.exe, .msi, .dll, .apk**).
* Click the Upload Binary button.
* Once the upload is complete, you will be redirected to your projects page.<br>

<br>


# Hybrid Deployment

Hybrid deployment keeps source code and artifacts inside your environment. Lineaje performs local analysis and sends only SBOM metadata to the Lineaje platform.

{% stepper %}
{% step %}

### Prerequisites

Complete the [prerequisites](/deploying-lineaje/hybrid-deployment/prerequisites) for system, network, and toolset configuration.&#x20;
{% endstep %}

{% step %}

### Deploy Lineaje Producs

* To deploy SBOM360, see [Deploying SBOM360](/deploying-lineaje/hybrid-deployment/deploying-sbom360).
* To deploy UnifAI, see [Deploying UnifAI](/deploying-lineaje/hybrid-deployment/deploying-unifai).
  {% endstep %}

{% step %}

### Register the CLI

After deploying SBOM360, [register the CLI](/deploying-lineaje/hybrid-deployment/installing-and-registering-the-cli#registering-the-cli).
{% endstep %}

{% step %}

### Use the CLI

To generate SBOMs for source code, package files, and container images, see [Using the CLI](/deploying-lineaje/hybrid-deployment/using-the-cli).
{% endstep %}
{% endstepper %}


# Prerequisites

Network configuration applies to every deployment mode. OVA also needs system configuration. AWS uses only network configuration. CLI Binary also needs system and toolset configuration.

* [System Configuration](/deploying-lineaje/hybrid-deployment/prerequisites/system-configuration)
* [Network Configuration](/deploying-lineaje/hybrid-deployment/prerequisites/network-configuration)
* [Toolset Configuration](/deploying-lineaje/hybrid-deployment/prerequisites/toolset-configuration)


# System Configuration

Before deploying Lineaje solutions, ensure your environment meets the following configuration requirements.

### Hardware for CBOM

| Requirement      | Minimum specification                         |
| ---------------- | --------------------------------------------- |
| Operating system | Linux (RHEL 8+, Ubuntu 20.04+, or equivalent) |
| CPU              | 4 cores                                       |
| RAM              | 20 GB                                         |
| Disk             | 250 GB SSD                                    |
| Network          | Outbound HTTPS access to \*.v2.prod.vdna.com  |

### Hardware for SBOM

<table><thead><tr><th width="198">Component</th><th>Requirements</th></tr></thead><tbody><tr><td>Processors</td><td><p>Intel x86_64 architecture-based processor</p><ul><li>Minimum: 2 vCPU</li><li>Recommended: 4 vCPU</li></ul></td></tr><tr><td>Memory</td><td><p>Minimum: 2 GB RAM</p><p>Recommended: 4 GB RAM </p></td></tr><tr><td>Disk space</td><td><p>Output Directory – Minimum 100 GB </p><p>“/tmp” Directory – Minimum 40 GB </p><p>“/home” Directory – Minimum 1 GB</p></td></tr></tbody></table>

### Operating System

* Ubuntu 22.04 LTS
* Red Hat Enterprise Linux 8

{% hint style="info" %}
The CLI does not support 32-bit platforms.
{% endhint %}

### Additional Software Requirement

The CLI requires the following software:

* Git Client

For language decomposition, see [Toolset Configuration](/sca360-secure-deployment-for-restricted-environments/toolset-configuration).

The following tools are recommended for troubleshooting:&#x20;

* `unzip`&#x20;
* `strace`
* `screen/tmux`
* `gdb`&#x20;
* `wget / curl`
* `vim`
* `tcpdump`
* `jq`


# Network Configuration

Configure the network access that SCA360 needs to run, such as outbound ports, runtime privileges, and external domains used for analysis, uploads, and report downloads. Allow only the services that apply to your environment and enabled features.

### Security and Firewall Requirements

<table><thead><tr><th width="154">Port</th><th>Usage</th></tr></thead><tbody><tr><td>TCP/443</td><td>SCA360 uses this port to connect to the SBOM360 backend and fetch data from public repositories.</td></tr></tbody></table>

### Privileges Configuration

<table><thead><tr><th width="154">Privilege type</th><th>Usage</th></tr></thead><tbody><tr><td>Regular User</td><td>SCA360 runs as a regular user. Root or sudo privileges are not required. The user must have a valid home directory.</td></tr><tr><td>Network access</td><td>SCA360 requires access to external networks on the ports listed in the Firewall Requirements table. Depending on the configuration, SCA360 may also require access to internal source and package repositories.</td></tr><tr><td>Execution access</td><td>SCA360 executes the following: third-party tools shipped in the <code>third_party</code> folder, and the <code>git</code> client to clone source code.</td></tr></tbody></table>

### Domains Requiring Access

Configure this only if the firewall does not allow outgoing HTTPS connections by default.

<table><thead><tr><th width="336.727294921875">Services accessed</th><th></th></tr></thead><tbody><tr><td>Lineaje Backend Services</td><td><p>https://*.v2.prod.veedna.com <strong>OR</strong></p><p>https://data-service-v2-apigw.v2.prod.veedna.com<br>https://notification-service.v2.prod.veedna.com</p><p>https://lineaje-gpt-service.v2.prod.veedna.com</p><p>https://lineaje-identity-service.v2.prod.veedna.com</p><p>https://scim-service.v2.prod.veedna.com</p></td></tr><tr><td>Upload SBOM metadata</td><td>https://us-east-1-commercialprod-veedna-opa.s3.amazonaws.com/*</td></tr><tr><td>Download reports</td><td>https://us-east-1-commercialprod-veedna-sbomreport-bucket.s3.amazonaws.com/*<br><br>https://us-east-1-commercialprod-veedna-datapipeline.s3.amazonaws.com/*</td></tr><tr><td>Local Vulnerability Lookup</td><td><p>https://*.anchore.io <strong>OR</strong></p><p>https://toolbox-data.anchore.io/<br>https://grype.anchore.io</p></td></tr><tr><td>Malware Lookup</td><td>https://data.reversinglabs.com</td></tr><tr><td>Maven and Gradle Package Repository</td><td><p>https://repo.maven.apache.org</p><p>https://repo1.maven.org</p><p>https://repo.spring.io</p><p>https://oss.sonatype.org</p><p>https://maven.google.com<br>https://dl.google.com</p></td></tr><tr><td>NPM and JavaScript Package Repository</td><td>https://registry.npmjs.org</td></tr><tr><td>Python Package Repository</td><td>https://pypi.org</td></tr><tr><td>Rust Package Repository</td><td>https://crates.io</td></tr><tr><td>Ruby Package Repository</td><td>https://rubygems.org</td></tr><tr><td>Dotnet Package Repository</td><td>https://api.nuget.org</td></tr><tr><td>Go Package Repository</td><td>https://sum.golang.org<br>https://proxy.golang.org<br>https://golang.org<br>https://google.golang.org<br>https://pkg.go.dev</td></tr><tr><td>Packagist Repository</td><td>https://packagist.org</td></tr><tr><td>Source Repository</td><td><p>https://github.com</p><p>https://bitbucket.org</p><p>https://gitlab.com</p></td></tr><tr><td>Ubuntu Container</td><td><p>https://*.ubuntu.com <strong>OR</strong> https://archive.ubuntu.com</p><p>https://security.ubuntu.com</p><p>https://old-releases.ubuntu.com</p></td></tr><tr><td>Debian Container</td><td>https://*.debian.org <strong>OR</strong><br>https://ftp.de.debian.org</td></tr><tr><td>Red Hat Container</td><td><p>https://*.redhat.com <strong>OR</strong><br>https://sso.redhat.com</p><p>https://api.access.redhat.com</p><p>https://cdn-ubi.redhat.com</p></td></tr><tr><td>Alpine Container</td><td><p>https://*.alpinelinux.org <strong>OR</strong><br>https://build.alpinelinux.org</p><p>https://dl-cdn.alpinelinux.org</p></td></tr><tr><td>Amazon Linux Container</td><td>https://*.amazonlinux.com <strong>OR</strong><br>https://cdn.amazonlinux.com</td></tr></tbody></table>


# Toolset Configuration

Local SBOM generation resolves a language-specific toolchain for each ecosystem a scan touches. The CLI prefers the system-installed toolchain when it meets the minimum version requirements and falls back to a pinned toolset under `third_party/linux` when the system toolchain doesn't qualify.

Toolset settings are read from `third_party/runtimes-config.json` and `third_party/tools-config.json`.&#x20;

Edit these files only to override a default tool path or version:

```bash
cd veecli
cat third_party/runtimes-config.json | jq . | less
cat third_party/tools-config.json | jq . | less
```

### Toolset Requirements

The CLI resolves toolsets independently for each of the following ecosystems, using the system toolchain wherever it qualifies.

* PyPI and Python
* npm and Node.js
* Maven and Gradle
* Cargo and Rust
* Ruby
* Go modules
* NuGet and .NET

### Use Native Python

Native Python resolution requires a system Python interpreter, `pipdeptree` version `2.3.3` or later, and virtual environment support.

```bash
cd veecli
which python
pip show pipdeptree
sudo pip install pipdeptree==2.3.3
python -m venv /tmp/python-venv
```

<details>

<summary>Set up Python on Ubuntu 22.04</summary>

#### Python 3.10

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y
sudo apt-get install libssl-dev libpq-dev libffi-dev libsqlite3-dev -y
sudo apt-get install python3-pip python3-venv -y

wget -q https://www.python.org/ftp/python/3.10.8/Python-3.10.8.tgz
tar -xzf Python-3.10.8.tgz
mkdir -p third_party/linux/python310
cd Python-3.10.8
./configure --prefix=$(pwd)/../third_party/linux/python310 > /dev/null 2>&1
make install > /dev/null 2>&1
cd -

ls -al third_party/linux/python310/bin/python3.10
sudo pip install pipdeptree==2.3.3

rm -f Python-3.10.8.tgz
rm -rf Python-3.10.8
```

#### Python 3.9

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y
sudo apt-get install libssl-dev libpq-dev libffi-dev libsqlite3-dev python3-pip -y

wget -q https://www.python.org/ftp/python/3.9.15/Python-3.9.15.tgz
tar -xzf Python-3.9.15.tgz
mkdir -p third_party/linux/python39
cd Python-3.9.15
./configure --prefix=$(pwd)/../third_party/linux/python39 > /dev/null 2>&1
make install > /dev/null 2>&1
cd -

ls -al third_party/linux/python39/bin/python3.9
sudo pip install pipdeptree==2.3.3

rm -f Python-3.9.15.tgz
rm -rf Python-3.9.15
```

</details>

### Use Native npm

Native npm resolution requires `npm` on the system path.

```bash
which npm
```

<details>

<summary>Set up npm on Ubuntu 22.04</summary>

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y
sudo apt-get install python2 libx11-dev libxkbfile-dev libkrb5-dev libsecret-1-dev -y

wget -q https://nodejs.org/dist/v16.20.2/node-v16.20.2-linux-x64.tar.xz
mkdir -p third_party/linux/node-16.20.2
tar --strip-components=1 -C third_party/linux/node-16.20.2 -xf node-v16.20.2-linux-x64.tar.xz

wget -q https://nodejs.org/dist/v18.19.0/node-v18.19.0-linux-x64.tar.xz
mkdir -p third_party/linux/node-18.19.0
tar --strip-components=1 -C third_party/linux/node-18.19.0 -xf node-v18.19.0-linux-x64.tar.xz

wget -q https://nodejs.org/dist/v21.4.0/node-v21.4.0-linux-x64.tar.xz
mkdir -p third_party/linux/node-21.4.0
tar --strip-components=1 -C third_party/linux/node-21.4.0 -xf node-v21.4.0-linux-x64.tar.xz

ls -al third_party/linux/node-16.20.2/bin/npm
ls -al third_party/linux/node-18.19.0/bin/npm
ls -al third_party/linux/node-21.4.0/bin/npm

rm node-v16.20.2-linux-x64.tar.xz
rm node-v18.19.0-linux-x64.tar.xz
rm node-v21.4.0-linux-x64.tar.xz
```

</details>

<details>

<summary>Set up npm on Red Hat Enterprise Linux 8</summary>

```bash
cd veecli
sudo yum check-update
sudo yum install git jq vim -y
sudo yum groupinstall "Development Tools" -y
sudo yum install dnf-utils pkg-config tar wget -y
sudo yum install python2 krb5-devel libsecret-devel -y

wget -q https://nodejs.org/dist/v16.20.2/node-v16.20.2-linux-x64.tar.xz
mkdir -p third_party/linux/node-16.20.2
tar --strip-components=1 -C third_party/linux/node-16.20.2 -xf node-v16.20.2-linux-x64.tar.xz

wget -q https://nodejs.org/dist/v18.19.0/node-v18.19.0-linux-x64.tar.xz
mkdir -p third_party/linux/node-18.19.0
tar --strip-components=1 -C third_party/linux/node-18.19.0 -xf node-v18.19.0-linux-x64.tar.xz

wget -q https://nodejs.org/dist/v21.4.0/node-v21.4.0-linux-x64.tar.xz
mkdir -p third_party/linux/node-21.4.0
tar --strip-components=1 -C third_party/linux/node-21.4.0 -xf node-v21.4.0-linux-x64.tar.xz

ls -al third_party/linux/node-16.20.2/bin/npm
ls -al third_party/linux/node-18.19.0/bin/npm
ls -al third_party/linux/node-21.4.0/bin/npm

rm node-v16.20.2-linux-x64.tar.xz
rm node-v18.19.0-linux-x64.tar.xz
rm node-v21.4.0-linux-x64.tar.xz
```

</details>

### Use Native Maven

Native Maven resolution requires Java and Maven on the system path.

```bash
which java
which mvn
```

<details>

<summary>Set up Maven on Ubuntu 22.04</summary>

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y

wget -q https://download.java.net/java/GA/jdk17.0.2/dfd4a8d0985749f896bed50d7138ee7f/8/GPL/openjdk-17.0.2_linux-x64_bin.tar.gz
mkdir -p third_party/linux/openjdk-17.0.2_linux-amd64
tar --strip-components=1 -C third_party/linux/openjdk-17.0.2_linux-amd64 -xzf openjdk-17.0.2_linux-x64_bin.tar.gz
ls -al third_party/linux/openjdk-17.0.2_linux-amd64/bin/java

mkdir -p third_party/linux/maven-3.8.8
wget -q https://dlcdn.apache.org/maven/maven-3/3.8.8/binaries/apache-maven-3.8.8-bin.tar.gz
tar --strip-components=1 -C third_party/linux/maven-3.8.8 -xzf apache-maven-3.8.8-bin.tar.gz
ls -al third_party/linux/maven-3.8.8/bin/mvn

export JAVA_HOME=$(pwd)/third_party/linux/openjdk-17.0.2_linux-amd64

rm openjdk-17.0.2_linux-x64_bin.tar.gz apache-maven-3.8.8-bin.tar.gz
```

</details>

<details>

<summary>Set up Maven on Red Hat Enterprise Linux 8</summary>

```bash
cd veecli
sudo yum check-update
sudo yum install git jq vim -y
sudo yum groupinstall "Development Tools" -y
sudo yum install dnf-utils pkg-config tar wget -y

wget -q https://download.java.net/java/GA/jdk17.0.2/dfd4a8d0985749f896bed50d7138ee7f/8/GPL/openjdk-17.0.2_linux-x64_bin.tar.gz
mkdir -p third_party/linux/openjdk-17.0.2_linux-amd64
tar --strip-components=1 -C third_party/linux/openjdk-17.0.2_linux-amd64 -xzf openjdk-17.0.2_linux-x64_bin.tar.gz
ls -al third_party/linux/openjdk-17.0.2_linux-amd64/bin/java

mkdir -p third_party/linux/maven-3.8.8
wget -q https://dlcdn.apache.org/maven/maven-3/3.8.8/binaries/apache-maven-3.8.8-bin.tar.gz
tar --strip-components=1 -C third_party/linux/maven-3.8.8 -xzf apache-maven-3.8.8-bin.tar.gz
ls -al third_party/linux/maven-3.8.8/bin/mvn

export JAVA_HOME=$(pwd)/third_party/linux/openjdk-17.0.2_linux-amd64

rm openjdk-17.0.2_linux-x64_bin.tar.gz apache-maven-3.8.8-bin.tar.gz
```

</details>

### Use Native Gradle

Native Gradle resolution requires Java and Gradle on the system path.

```bash
which java
which gradle
```

<details>

<summary>Set up Gradle on Ubuntu 22.04</summary>

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y

wget -q https://download.java.net/java/GA/jdk17.0.2/dfd4a8d0985749f896bed50d7138ee7f/8/GPL/openjdk-17.0.2_linux-x64_bin.tar.gz
mkdir -p third_party/linux/openjdk-17.0.2_linux-amd64
tar --strip-components=1 -C third_party/linux/openjdk-17.0.2_linux-amd64 -xzf openjdk-17.0.2_linux-x64_bin.tar.gz
ls -al third_party/linux/openjdk-17.0.2_linux-amd64/bin/java

wget -q https://services.gradle.org/distributions/gradle-7.5.1-bin.zip
unzip -q gradle-7.5.1-bin.zip -d third_party/linux
ls -al third_party/linux/gradle-7.5.1/bin/gradle

export JAVA_HOME=$(pwd)/third_party/linux/openjdk-17.0.2_linux-amd64

rm openjdk-17.0.2_linux-x64_bin.tar.gz gradle-7.5.1-bin.zip
```

</details>

### Use Native Cargo

Native Cargo resolution requires Cargo and `cargo-lock`, ideally installed to the same location.

```bash
which cargo
which cargo-lock
```

<details>

<summary>Set up Cargo on Ubuntu 22.04</summary>

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y
sudo apt-get install libssl-dev -y

curl -s https://sh.rustup.rs -o rust.sh
export RUSTUP_HOME=$(pwd)/third_party/linux/rustup
export CARGO_HOME=$(pwd)/third_party/linux/cargo
bash rust.sh -y -q > /dev/null 2>&1

ls -al third_party/linux/cargo/bin/cargo
third_party/linux/cargo/bin/cargo install -q --root $(pwd)/third_party/linux/cargo cargo-lock --features=cli

rm rust.sh
```

</details>

### Use Native Ruby

Native Ruby resolution requires Ruby, Bundler, RubyGems, the `bundler-graph` plugin, and the `ruby-graphviz` and `cyclonedx-ruby` gems.

```bash
which ruby
which bundle
which gem
bundle plugin list
gem list ruby-graphviz
which cyclonedx-ruby
gem specification cyclonedx-ruby version
echo $BUNDLE_PATH
echo $GEM_PATH
```

<details>

<summary>Set up Ruby on Ubuntu 22.04</summary>

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y
sudo apt-get install libyaml-dev graphviz libsqlite3-dev libssl-dev zlib1g-dev -y

wget -q https://cache.ruby-lang.org/pub/ruby/3.2/ruby-3.2.2.tar.gz
mkdir -p third_party/linux/ruby-3.2.2
tar -xzf ruby-3.2.2.tar.gz
cd ruby-3.2.2
./configure --prefix=$(pwd)/../third_party/linux/ruby-3.2.2 > /dev/null 2>&1
make install > /dev/null 2>&1
cd -

ls -al third_party/linux/ruby-3.2.2/bin/ruby
mkdir -p $(pwd)/third_party/linux/ruby-gems

export PATH=$PATH:$(pwd)/third_party/linux/ruby-3.2.2/bin
export BUNDLE_PATH=$(pwd)/third_party/linux/ruby-gems
export GEM_PATH=$(pwd)/third_party/linux/ruby-gems

./third_party/linux/ruby-3.2.2/bin/bundle plugin install bundler-graph
./third_party/linux/ruby-3.2.2/bin/gem install ruby-graphviz

git clone https://github.com/lineaje-labs/cyclonedx-ruby-gem.git
cd cyclonedx-ruby-gem
git checkout ffe6a1a6d78efafc02c47c1c6c245a0082bfa68a
gem build cyclonedx-ruby.gemspec
gem install cyclonedx-ruby-1.2.0.lineaje.gem > /dev/null 2>&1
cd -
rm -rf cyclonedx-ruby-gem
```

</details>

### Use Native Go

Native Go resolution requires a system Go installation and `cyclonedx-gomod` version `1.3.0` or later.

```bash
which go
which cyclonedx-gomod
cyclonedx-gomod version
wget -q https://github.com/CycloneDX/cyclonedx-gomod/releases/download/v1.3.0/cyclonedx-gomod_1.3.0_linux_amd64.tar.gz
tar -xzf cyclonedx-gomod_1.3.0_linux_amd64.tar.gz
sudo cp cyclonedx-gomod /usr/sbin
echo $GOROOT
```

<details>

<summary>Set up Go on Ubuntu 22.04</summary>

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y

wget -q https://golang.google.cn/dl/go1.18.10.linux-amd64.tar.gz
mkdir -p third_party/linux/go-1.18
tar --strip-components=1 -C third_party/linux/go-1.18 -xzf go1.18.10.linux-amd64.tar.gz
ls -al third_party/linux/go-1.18/bin/go

mkdir -p third_party/linux/cyclonedx-gomod-1.3
wget -q https://github.com/CycloneDX/cyclonedx-gomod/releases/download/v1.3.0/cyclonedx-gomod_1.3.0_linux_amd64.tar.gz
tar -C third_party/linux/cyclonedx-gomod-1.3 -xzf cyclonedx-gomod_1.3.0_linux_amd64.tar.gz
ls -al third_party/linux/cyclonedx-gomod-1.3/cyclonedx-gomod

export GOROOT=$(pwd)/third_party/linux/go-1.18
export PATH=$PATH:$GOROOT/bin

rm go1.18.10.linux-amd64.tar.gz cyclonedx-gomod_1.3.0_linux_amd64.tar.gz
```

</details>

### Use Native NuGet

Native NuGet resolution requires `dotnet` and `dotnet-cyclonedx` on the system path.

```bash
which dotnet
which dotnet-cyclonedx
echo $DOTNET_ROOT
```

<details>

<summary>Set up NuGet on Ubuntu 22.04</summary>

```bash
cd veecli
sudo apt-get update
sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y

wget -q https://dot.net/v1/dotnet-install.sh -O dotnet-install.sh
chmod +x ./dotnet-install.sh
mkdir -p third_party/linux/dotnet

bash ./dotnet-install.sh --install-dir third_party/linux/dotnet -c LTS > /dev/null 2>&1
bash ./dotnet-install.sh --install-dir third_party/linux/dotnet -c STS > /dev/null 2>&1
bash ./dotnet-install.sh --install-dir third_party/linux/dotnet -c 6.0 > /dev/null 2>&1

ls -al third_party/linux/dotnet/dotnet

export DOTNET_ROOT=$(pwd)/third_party/linux/dotnet
export PATH=$PATH:$(pwd)/third_party/linux/dotnet:$(pwd)/third_party/linux/dotnet/tools

mkdir -p third_party/linux/cyclonedx-dotnet
dotnet tool install --tool-path $(pwd)/third_party/linux/cyclonedx-dotnet CycloneDX > /dev/null 2>&1
ls -al third_party/linux/cyclonedx-dotnet/dotnet-CycloneDX

rm dotnet-install.sh
```

</details>


# Deploying SBOM360

SBOM360 provides continuous software supply chain security management by mapping the lineage of your programs. It helps you generate and analyze Software Bills of Materials, assess risk across dependencies, and protect against software supply chain attacks.

Choose a deployment mode for deploying SBOM360.

<details>

<summary>CLI Binary</summary>

With CLI Binary, you can deploy and manage SBOM360 on your own VM.

Download the CLI from the Lineaje Portal, then complete installation in [Installing CLI](/deploying-lineaje/hybrid-deployment/installing-and-registering-the-cli#installing-cli).

</details>

<details>

<summary>AWS Marketplace</summary>

You can deploy Lineaje SCA360 in your AWS environment by subscribing to the Lineaje service and creating a stack and then configuring the instance in the Lineaje Portal.

### Step 1: Deploying Lineaje SCA360 Through AWS Marketplace

1. Log in to the AWS Marketplace and search for `Lineaje SCA360` in the AWS Marketplace products.

   <figure><img src="/files/bss7xSy8O6AJqbfSXrdr" alt="Search for Lineaje in AWS Marketplace"><figcaption></figcaption></figure>
2. Click on **View purchase options** and click **Subscribe**.

   <figure><img src="/files/3spgRSn7k1ur3ykBUfQD" alt="Lineaje purchase options"><figcaption></figcaption></figure>
3. Click **Set up your account** and enter the details.

   <figure><img src="/files/cH7955E4q6Ad7d76QxZ0" alt="Enter account details"><figcaption></figcaption></figure>
4. Click **Next**.
5. Click **Deploy** to set up SCA360 in your preferred AWS region.
6. On the **Stacks** page, a pre-filled CloudFormation template is displayed. Enter the following information:

   * **VPC ID**: Choose your preferred VPC to define the network boundary of your AWS resources. VPC ID must be created prior to deployment. To learn more, see [Prerequisites](https://veedna.atlassian.net/wiki/spaces/~712020229c992a6cc548239d3993932adc913d/pages/1024163841/Tech+Writer+Copy+Lineaje+SCA360+Installation#Prerequisites).
   * **Subnet ID**: Choose a subnet where your resources will be launched within the VPC. Subnet ID must be created prior to deployment. To learn more, see [Prerequisites](https://veedna.atlassian.net/wiki/spaces/~712020229c992a6cc548239d3993932adc913d/pages/1024163841/Tech+Writer+Copy+Lineaje+SCA360+Installation#Prerequisites).
   * **CIDR IP Range**: Enter `0.0.0.0/0`. Accesses the VM or EC2 instance to allow access of all IP addresses. To allow a specific IP address access, set CIDR to `x.x.x.x/32`.
   * **Key Pair**: Select the Key Pair. Key Pair must be created prior to deployment. To learn more, see [Prerequisites](https://veedna.atlassian.net/wiki/spaces/~712020229c992a6cc548239d3993932adc913d/pages/1024163841/Tech+Writer+Copy+Lineaje+SCA360+Installation#Prerequisites).

   <figure><img src="/files/an4UvhnbOvA0FWN5Mcd3" alt="Aws stacks page"><figcaption></figcaption></figure>
7. Under **Capabilities**, check **I acknowledge that that AWS CloudFormation might create IAM resources**.
8. Click **Create stack.**

### Step 2: Configuring Lineaje SCA360 in the Lineaje Portal

1. Log in to the [Lineaje Portal](https://app.veedna.com/).
2. In the left-hand navigation, select **Integrations**.
3. Click **Scan Remotely** to create an SBOM by connecting to your relevant SCM or Container Registry. Click **Upload and Scan** > **Upload Manifest File** if you want to generate SBOM by uploading a Manifest File.

   <figure><img src="/files/YsoZ7nNPpn5kw8Sb5mM1" alt="Scan remotely"><figcaption></figcaption></figure>
4. To create an SBOM using your GitHub repository:

   1. In **Scan Remotely**, select **GitHub**.
   2. In the **Details** section, enter a name for your integration and enter a GitHub link.
   3. Click **Next**.

   <figure><img src="/files/kAhZ6BMpXm8dhfP4WRFX" alt="Add details"><figcaption></figcaption></figure>
5. In the **Repositories** section, select the tag or branch you want to scan from your GitHub repository and click **Save Configuration**.

   <figure><img src="/files/UfzGdB8pO5MwXWfZ5ywQ" alt="Select tag or branch"><figcaption></figcaption></figure>
6. Under **Project Name**, click on your project to view the enriched SBOM.
7. Click **Actions** to download the SBOM.

   <figure><img src="/files/8FCrnkkFQ0lwOU8PScPw" alt="Download the SBOM"><figcaption></figcaption></figure>

</details>

<details>

<summary>Open Virtual Appliance (OVA)</summary>

Set up your Windows 11 environment to deploy Lineaje SCA360. Install the required components, configure a virtual machine, and deploy SCA360 using Gitbash.

### **Step 1: Installing the Required Components**

Install the following on your Windows 11 system (use default settings):

* [Python 3](https://www.python.org/downloads/windows/)
* [Git Bash](https://git-scm.com/install/windows)
* [Oracle VirtualBox](https://www.virtualbox.org/wiki/Downloads)

### **Step 2: Setting Up a Virtual Machine**

1. Download the OVA file from the SharePoint link sent to your email address.
2. Open **Oracle VirtualBox** > **File** > **Import Virtual Application**.
3. Select the OVA file and click **Finish**.
4. After import, go to **Settings**.

   <div align="left"><figure><img src="/files/BCgXGdAXWwjPgW46iyLk" alt="Settings"><figcaption></figcaption></figure></div>
5. In the **System** section, set **Base Memory** to **4096 MB**.

   <figure><img src="/files/p57VAbFjfAYFboeCY6T0" alt="System section"><figcaption></figcaption></figure>
6. In the **Network** section, click on **Port Forwarding**.

   <figure><img src="/files/DVSq0DKgD2Rwux3aXNdG" alt="Port forwarding"><figcaption></figcaption></figure>
7. Create a new rule with the following configuration:
   * **Name**: SSH
   * **Protocol**: TCP
   * **Host IP**: 127.0.0.1
   * **Host Port**: 2222
   * **Guest Port**: 22

<figure><img src="/files/ZaZkbDjArHVWkSbc8YwK" alt="New rule configuration"><figcaption></figcaption></figure>

8. Click **OK**.
9. Click **OK** to save the settings. 8. Start the virtual machine. 9. Log in using the following credentials:
   * Username: `lineaje`
   * Password: `lineaje`

{% hint style="info" %}
The default host key is the right Ctrl key. The minimum disk space is 20 GB. For POC, a minimum 100 GB is recommended.
{% endhint %}

10. Confirm that the CLI is installed correctly by checking its version.

`./veecli --version`

{% hint style="info" %}
If SSH or download fails, type the command sudo dhclient. Verify that the virtual machine has internet connectivity by performing a simple network check, such as sending a ping request to a reliable website (e.g., Google).
{% endhint %}

</details>

#### Next steps

After deployment, complete these steps for all modes:

1. [Registering CLI](/deploying-lineaje/hybrid-deployment/installing-and-registering-the-cli#registering-cli)
2. [Using the CLI](/deploying-lineaje/hybrid-deployment/using-the-cli)


# Deploying UnifAI

UnifAI is the unified AI security orchestrator for agentic AI application development. It secures AI applications as they are built, applies corporate security policies in real time, and continuously discovers AI assets so developers can build secure applications with integrated controls.

To deploy UnifAI, see [Setting Up](/unifai/setting-up).


# Installing and Registering the CLI

Use this guide to install the CLI on your VM, register it with Lineaje, or deregister it when you no longer need it.

<details>

<summary>Installing the CLI</summary>

Download the CLI from the Lineaje Portal, extract it on your VM, and register it with your device code.

1. Log in to the [Lineaje Portal](https://app.veedna.com/auth/signup).
2. From the left-hand navigation, choose **Integrations**.
3. Under **SCA360**, click **Download SCA360**.
4. Extract the CLI using the following steps:

```
# Run these commands as a regular user
# Extract the veecli.tar.gz
ubuntu@ip-a.b.c.d:~$ tar -xzf veecli.tar.gz
# This will create a directory called veecli
ubuntu@ip-a.b.c.d:~$ cd veecli
# Run pre.sh to set the permissions of the CLI and associated files
ubuntu@ip-a.b.c.d:~$ bash pre.sh
```

5. Go to the Lineaje Portal and click **Verify Device**.

<figure><img src="/files/vwblQGscLU95tENsg0Oj" alt=""><figcaption></figcaption></figure>

6. Click **Verify Link**. The device confirmation code appears.

<div align="left"><figure><img src="/files/a8W9Wtw0XgSISu0TkSpq" alt=""><figcaption></figcaption></figure></div>

7. Click **Confirm**.
8. Provide your credentials, if prompted.

</details>

<details>

<summary>Registering the CLI</summary>

1. After device registration succeeds, copy the code shown in the Lineaje Portal. The device registration code is valid for 5 minutes. If it expires, click **Verify Device** → **Verify Link** to get a new code.

<div align="right"><figure><img src="/files/ZrM8dwVQYDM72OB1EvzZ" alt=""><figcaption></figcaption></figure></div>

2. Run the following commands from the Ubuntu machine where the CLI is extracted.

```
# Run these commands as a regular user
# Go inside the directory where CLI is extracted
ubuntu@ip-172-31-26-185:~$ cd veecli
# Register the CLI with the SBOM360 backend using the device code obtained from portal
ubuntu@ip-172-31-26-185:~$ ./veecli register --devicecode npbP_fImda2Cj_Hzk9LgxJUn
2022-07-07T14:18:15.584+0300 info Starting to register veeCLI
2022-07-07T14:18:16.924+0300 info Successfully configured authentication
2022-07-07T14:18:16.924+0300 debug Signature in auth0 access token payload is 
unknown
2022-07-07T14:18:16.933+0300 info Authenticated for Tenant Name - ******, Tenant 
Id - vdna_************** and Device Code - npbP_fImda2Cj_Hzk9LgxJUn
2022-07-07T14:18:16.934+0300 info Successfully registered veeCLI
```

</details>

<details>

<summary>Deregistering the CLI</summary>

Deregister the CLI when you want to stop it from communicating with the Lineaje backend.

```bash
cd veecli
./veecli deregister --force
```

</details>


# Using the CLI

Use the CLI to generate SBOMs for source code, package files, and container images. SBOMs appear on the Projects page after upload. Generation time varies from a few seconds to several hours, depending on project size. The CLI collects metadata at n levels of depth, covering each component, its direct dependencies, and its transitive dependencies.

Ensure the `output` folder has at least 100 GB of free space.

Depending on the size of the source, packages, and dependencies discovered, the CLI may take a significant amount of time to complete. Run the CLI inside a `screen` or `tmux` session to prevent an interrupted user session from breaking the CLI run.

The CLI creates a JSON log file named `veelocal.log` in the current directory. To also capture CLI output, redirect it to a separate log file:

`./veecli collect --inputfile input.json --output output 2>&1 | tee output.log`

This page covers common collection and upload workflows across local files, Docker, Docker Hub, Amazon ECR, and Azure Container Registry.

<details>

<summary>Generate an SBOM From an Input JSON</summary>

Provide an input file and an output directory.

The output directory is used for checkout, downloads, extraction, and artifacts.

```bash
cd veecli
./veecli collect --inputfile input.json --output output
```

Example output:

```
2022-07-07T14:18:15.584+0300 info Starting data collection
2022-07-07T14:18:16.924+0300 info SBOM created for project acme and version 2.10.5 with project id - ***, sbom id - SPDXRef-DOCUMENT-vdna_*****, sbom job id - SPDXRef-DOCUMENT-vdna_****
...
2022-07-07T14:18:16.934+0300 info Successfully uploaded archive of collection artifacts – output/acme/acme-SPDXRef-DOCUMENT-vdna_******.tar.gz
2022-07-07T14:18:16.934+0300 info Successfully completed data collection
```

Keep at least `100 GB` free in the output directory.

Large scans can run for a while.

Use `screen` or `tmux` for long-running jobs.

The CLI also writes a JSON log file named `veelocal.log` in the current directory.

A common pattern is:

```bash
./veecli collect --inputfile input.json --outpath output 2>&1 | tee output.log
```

#### Generating SBOM From Source Code

Run the CLI using the following command. The CLI decomposes source code locally and uploads only the metadata to the Lineaje backend. Metadata includes package information (name, version, checksum) and source code information (URL, version, commits, timezone).

```
./veecli collect --inputfile <input.json> --output <output_path>
```

**Open Source examples of input.json**

```json
Maven project
{
  "project": "maven project",
  "version": "0.9.125",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "github",
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://github.com/cloudera/cdp-sdk-java",
        "matchingref": "0.9.125",
        "type": "github"
      }
    }
  ]
}

Gradle project
{
  "project": "gradle project",
  "version": "parent-4.12.0",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "github",
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://github.com/square/okhttp",
        "matchingref": "parent-4.12.0",
        "type": "github"
      }
    }
  ]
}

Python project
{
  "project": "pypi project",
  "version": "v1.9.2",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "github",
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://github.com/aio-libs/yarl",
        "matchingref": "v1.9.2",
        "type": "github"
      }
    }
  ]
}

go-lang project
{
  "project": "golang project",
  "version": "v0.10.0",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "github",
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://github.com/charmbracelet/lipgloss.git",
        "matchingref": "v0.10.0",
        "type": "github"
      }
    }
  ]
}

NPM project
{
  "project": "npm project",
  "version": "v8.4.0",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://github.com/bevry/cson",
        "type": "github",
        "matchingref": "v8.4.0"
      }
    }
  ]
}

Rust project
{
  "project": "rust project",
  "version": "v0.2.7",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "github",
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://github.com/redcanaryco/oxidebpf",
        "matchingref": "v0.2.7",
        "type": "github"
      }
    }
  ]
}

Ruby project
{
  "project": "ruby project",
  "version": "v3.4.2",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "github",
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://github.com/rails/sprockets-rails",
        "type": "github",
        "matchingref": "v3.4.2"
      }
    }
  ]
}

Nuget project
{
  "schema": "1.0",
  "project": "sanity project",
  "version": "13.0.1",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "github",
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://github.com/JamesNK/Newtonsoft.Json",
        "type": "github",
        "matchingref": "13.0.1"
      }
    }
  ]
}

PHP project
{ 
"project": "php project", 
"version": "1.0.0", 
"exclude_test_dependency": true, 
"inputtype": "github", 
"inputs": [ 
   { 
     "src_info": { 
       "srcurl": "https://github.com/akaunting/akaunting", 
       "matchingref": "master", 
       "type": "github" 
     } 
   } 
 ] 
} 
```

**Private source example of input.json**

```json
{
  "project": "<private-repo-name>",
  "version": "<branch/tag/commit-id>",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "<github/gitlab/bitbucket/git>",
  "inputs": [
    {
      "src_info": {
        "srcurl": "<private repo url>",
        "matchingref": "<branch/tag/commit-id>",
        "type": "<github/gitlab/bitbucket/git>"
      }
    }
  ],
  "repository_access_configs": [
    {
      "path": "<private repo url>",
      "type": "<github/gitlab/bitbucket/git>",
      "user_name": "<user-name>",
      "token": "<auth-token>"
    }
  ]
}

A sample bitbucket private repo
{
  "project": "curl-private-1",
  "version": "main",
  "exclude_test_dependency": true,
  "exclude_optional_dependency": true,
  "use_native_tools": true,
  "inputtype": "github",
  "inputs": [
    {
      "src_info": {
        "srcurl": "https://bitbucket.org/1234/curl-private",
        "matchingref": "main",
        "type": "bitbucket"
      }
    }
  ],
  "repository_access_configs": [
    {
      "path": "https://bitbucket.org/1234/curl-private",
      "type": "bitbucket",
      "user_name": "x-token-auth",
      "token": "1234567890"
    }
  ]
}
```

</details>

<details>

<summary>Generate an SBOM From Files in a Directory</summary>

Use `upload` when you want to scan a directory and send the result to the backend.

All fields are required.

```bash
cd veecli
./veecli upload --input dir --type folder --name my-project --version 1.0
```

</details>

<details>

<summary>Generate an SBOM From WAR or EAR Files in a Directory</summary>

Use `collect` when the directory contains `WAR` or `EAR` packages.

You must provide the project name and version.

```bash
cd veecli
./veecli collect --input-dir package-dir --output output --project my-project --version 1.0
```

</details>

<details>

<summary>Generate an SBOM From Local Docker</summary>

The CLI supports two approaches:

1. Upload the image manifest and generate the SBOM in the backend.
2. Generate the SBOM locally and upload the collected results.

Backend generation is faster.

Local generation uses more disk and CPU.

</details>

<details>

<summary>Generate an SBOM From Public Docker Hub</summary>

</details>

<details>

<summary>Generate an SBOM From Private Docker Hub</summary>

</details>

<details>

<summary>Generate an SBOM From Private Amazon ECR</summary>

Before you scan a private ECR image:

1. Create an IAM role with the required permissions.
2. Install and configure the AWS CLI.
3. Run `docker login` with an ECR token.

Grant at least these AWS permissions:

* `AmazonEC2ContainerRegistryReadOnly`
* `AmazonElasticContainerRegistryPublicReadOnly`

The CLI supports Docker Community Engine.

Docker installed through Ubuntu `snap` is not supported.

</details>

<details>

<summary>Generate an SBOM From Public Amazon ECR</summary>

</details>

<details>

<summary>Generate an SBOM From Private Azure Container Registry</summary>

Private ACR access requires registry access keys.

Set the username and password before running the scan.

</details>

<details>

<summary>Generate an SBOM From Public Azure Container Registry</summary>

</details>

<details>

<summary>Generate an SBOM From An Image</summary>

To scan an open source container image, run the following command. The example below uses `alpine:3.18.0` from Docker Hub.

**Open Source image example**

```json
./veecli upload --type image-source --input registry:docker.io/library/alpine:3.18.0 --name alpine --version 3.18.0
```

**Private image example**

```
export LINEAJE_REGISTRY_AUTH_USERNAME=<docker-login-username>
export LINEAJE_REGISTRY_AUTH_PASSWORD=<docker-login-password>
 
./veecli upload --type image-source --input registry:<repourl>:<tag> --name <project_name> --version <version>
```

</details>


# SBOM360

## SBOM360

SBOM360 provides continuous software supply chain security management to companies by mapping out the lineage of their programs. SBOM360 is an advanced solution that helps companies protect themselves from software supply chain attacks. Through SBOM360, anyone can prepare a Software Bill of Materials (SBOM) to keep themselves and their stakeholders safe.

Here are things that you can use SBOM360 for:

* Generate SBOM for your source repo or container image or an already existing SBOM file
* View overall risk score of your SBOM
* View transitive dependencies of your SBOM
* View vulnerabilities of your SBOM
* View licenses and suppliers of your SBOM
* View inherent risk for each component based on security posture, code quality
* Download assessment report of your SBOM
* Publish your SBOM to SBOM360 Hub
* Create policies and programs as per the organizational needs
* Evaluate SBOMs against programs and generate findings


# Setting Up

You can set up SBOM360 using either SaaS deployment or Hybrid deployment models.

* [Set up SBOM360 using SaaS](/deploying-lineaje/saas-deployment)
* [Set up SBOM360 using Hybrid](/deploying-lineaje/hybrid-deployment)


# Generate an SBOM

Generate SBOM via Integrations

There are different ways in which you can generate an SBOM project. You can get started by clicking on Integrations page as shown below

<figure><img src="/files/KTlJyTt0AsZQnijQaBCA" alt=""><figcaption></figcaption></figure>

There are different starting points for SBOM creation

1. [Source Code Management (SCM) As Source](/sbom360/generate-an-sbom/source-code-management-scm-as-source)
2. [Container Image As Source](/sbom360/generate-an-sbom/container-image-as-source)
3. [Existing SBOM As Source](/sbom360/generate-an-sbom/existing-sbom-as-source)
4. [Manifest file As Source](/sbom360/generate-an-sbom/manifest-file-as-source)
5. [Android Package Kit(APK)](/sbom360/generate-an-sbom/binary-files)
6. [Using Lineaje CLI](broken://pages/KRRYtcm2nGOLqMrZxpX4)

\ <br>


# Source Code Management (SCM) As Source

SBOM360 supports integration with different SCM systems.

### Source Code Management (SCM)

* Create a configuration for SCM integration.
* Each configuration can store settings for private or public code repositories.
* In case of [public code repositories](/sbom360/generate-an-sbom/source-code-management-scm-as-source/public-code-repositories), one configuration can store up to 10 public code repository URLs.
* In case of [private code repositories](/sbom360/generate-an-sbom/source-code-management-scm-as-source/private-code-repositories), credentials must be specified that carries enough permissions to enumerate and list the private code repositories.


# Public Code Repositories

SBOMs can be generated for public code repositories.

&#x20;There are two steps involved:

### Step 1: Details

* Each configuration can store up to 10 public code repository URLs
* Each repository URL is verified for its accessibility and a status is displayed

![](/files/bnfawkE1nEbEEfy1dniW)

### **Step 2: Review**

* The branches and tags for the verified code repositories are listed in this step
* Either a branch or tag can be selected for the each code repository
* Project name and version will be auto generated but can be edited
* Click on Save Configuration to generate SBOM

![                                                               ](/files/FTZDlMdS85Gtnl3ijGTb)


# Private Code Repositories

SBOMs can be generated for private code repositories.

## Configure access to private code

Private code configuration requires credentials to access the private code. This may include a combination of access token, username, certificates depending on the SCM platform. In general, the configuration has two steps

<figure><img src="/files/oTvR87VYBwbkMxQcjCNm" alt=""><figcaption></figcaption></figure>

### Step 1: Details

* Add credentials to access the private code. This may include a combination of access token, username, certificates depending on the SCM platform.
* By clicking Test Connection, the connection will be tested against the credentials.

### **Step 2: Review**

* All the repositories associated with credentials will be displayed
* Either a branch or tag can be selected for the each code repository
* Project name and version will be auto generated based on repo name and branch/tag. It can be edited.
* Click on Save Configuration to generate project.

![](/files/eAPBHovwi2futPQhJA2I)


# Configure GitHub credentials

GitHub configuration requires a "Personal Access Token".

## Creating Personal Access Token

Refer [GitHub docs](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens) to create Personal Access Token.

* Go to [github.com](https://github.com/) and sign-in
* Select your profile.
* Click on Settings.
* Click on Developer Settings.
* Click on Personal access tokens.
* Enter a token name.
* Set an expiration date (optional).
* Define scopes with the following permissions:
  * Repository – contents – read
  * Repository – metadata – read
* Click on Create personal access token.
* Add the newly generated token as "Access Token" in Lineaje configuration.


# Configure Bitbucket credentials

Bitbucket configuration requires "User Name" and "Access Token".

Bitbucket supports two types of access tokens depending on the access privileges. There are two types of tokens that can be generated based on your access rights to Bitbucket.

## Creating App password

Refer [Bitbucket Docs](https://support.atlassian.com/bitbucket-cloud/docs/create-an-app-password/) to learn about creating App password.

* Go to [bitbucket.org](https://bitbucket.org/).
* Go to your repository.
* Select the Settings cog in the upper-right corner of the top navigation bar.
* Under **Personal settings**, select **Personal Bitbucket settings.**
* On the left sidebar, select App passwords.
* Select Create app password, select permissions and save.
* Set the "User Name" in Lineaje configuration to your Bitbucket username. Please note that bitbucket username may not be the same as your email id.
* Add the newly generated token as "Access Token" in Lineaje configuration.

## Creating Access Tokens

Refer [Bitbucket Docs](https://support.atlassian.com/bitbucket-cloud/docs/access-tokens/) to learn about creating Repository/Project/Workspace Access Tokens and [creating](https://support.atlassian.com/bitbucket-cloud/docs/create-a-repository-access-token/) the repository tokens.

* Go to [bitbucket.org](https://bitbucket.org/).&#x20;
* Go to your repository.
* Click Repository Settings.
* Select Access tokens.
* Press Create Repository Access Token.
* Create a token name.
* Select the repository token permissions.
* Click the Create button.
* Copy the token and save it somewhere memorable. The token will be inaccessible once you leave the page.
* As per the Bitbucket docs, set the "User Name" to "**x-token-auth**" in Lineaje configuration.
* Add the newly generated token as "Access Token" in Lineaje configuration.


# Configure Gitlab credentials

Gitlab configuration requires "User Name" and "Access Token".

## Creating Personal Access Token

Refer [Gitlab docs](https://docs.gitlab.com/ee/user/profile/personal_access_tokens.html) to create Personal Access Token.

* Go to [about.gitlab.com](https://about.gitlab.com/) and sign-in
* Select your profile.
* Click Edit profile.
* Click on Access Tokens.
* Enter a token name.
* Set an expiration date (optional).
* Define scopes.
* Click on Create personal access token.
* Set the "User Name" in Lineaje configuration.
* Add the newly generated token as "Access Token" in Lineaje configuration.


# Configure Git credentials

git configuration requires "User Name" and "Access Token". The exact steps of creating the access token depends on the git cloud that is used.

## Creating Personal Access Token

* Depending on the git cloud used, follow the instructions to generate a personal access token.
* Set the "User Name" in Lineaje configuration.
* Add the newly generated token as "Access Token" in Lineaje configuration.


# Configure Azure Repo

Azure Repo uses standard git interface. Azure Repo can be configured using "[Git](/sbom360/generate-an-sbom/source-code-management-scm-as-source/private-code-repositories/configure-git-credentials)".

* Login to your account in [dev.azure.com](https://dev.azure.com)
* Top right corner, click on User Settings
* Click on Personal Access Token
* Click on "New Token"
* Add Name, Organization, Expiration, Scopes (Read access is preferred)

<figure><img src="/files/3WkM10k2WkUaakTJseje" alt=""><figcaption></figcaption></figure>


# Frequently Asked Questions

### Why do I not see a new project triggered even after clicking on "Save Configuration"?

Project generation has a n optimization to avoid accidental runs of same project configuration. A combination of Project Name and Version is used to generate a unique identifier for each project. A project run is triggered only if the combination of Project Name and Version does not exist.

### How can I change the settings for an existing project?

To change the configure, click on edit configuration.

* Step 1 (Details): Configuration name, description, credentials, repo URLs can be modified.
* Step 2 (Review): Branch/tag can be changed for the existing configuration by going to "Edit Repositories" tab.
* Click on Save Configuration to trigger a new project.

### How can I rerun a project for the same configuration?

To re-run a project for the same configuration, edit an existing configuration.&#x20;

* Step 1 (Details): No change. Click next.
* Step 2 (Review): Go to "Edit Repositories" tab.
* Click on Rescan SBOM. Remove repos that are not required for rescan.
* Click on Save Configuration to trigger a new project.

<figure><img src="/files/4ObG4UrOCF0nj3H8Ffr9" alt=""><figcaption></figcaption></figure>


# Container Image As Source

SBOM360 supports integration with different container registries.

* Create a configuration for container image integration. This helps the organizations to group image registries based on location or team or product.
* Each configuration can store settings for private or public image registry
* In case of [public image registry](/sbom360/generate-an-sbom/container-image-as-source/public-container-image), one configuration can store up to 10 public image URLs
* In case of [private code registry](/sbom360/generate-an-sbom/container-image-as-source/private-container-image), access must be given to enumerate and list the private container images.

<br>


# Public Container Image

SBOMs can be generated for public container images. There are two steps involved:

### Step 1: Details

* Each configuration can store up to 10 container image URLs
* Each container image URL is verified for its accessibility and a status is displayed

<figure><img src="/files/98faCftk4BE4uhDLIdPK" alt=""><figcaption></figcaption></figure>

### Step 2: Review

* The tags available for the verified conatiner image are listed in this step
* Choose a tag to generate an SBOM
* Project name and version will be auto generated but can be edited
* Click on “Save Configuration” to generate SBOM

<figure><img src="/files/NqBZDBDTyzgnkONSYUCX" alt=""><figcaption></figcaption></figure>

<br>


# Private Container Image

SBOMs can be generated for private code repositories.

There are three steps involved:

### Step 1: Details

* Each configuration requires a mandatory name and a description.

<figure><img src="/files/xk5jGnEvIiVuj6OfSAQz" alt=""><figcaption></figcaption></figure>

### Step 2: Configure

* Enter the credentials required to access the private registry. This gives Lineaje access to your organization’s private image registry,
* This step varies for AWS-ECR, GCP-Container Registry, and Docker Hub.
* By clicking on Test Connection, the connection will be tested against the credentials.

<figure><img src="/files/Izf2znNM3UrYLZI4Ujvq" alt=""><figcaption></figcaption></figure>

### Step 3: Review

* All the container images available in the private registry will be displayed
* Choose a container image
* Project name and version will be auto generated but can be edited
* Click on Save Configuration to generate a project


# Configure AWS Elastic Container Registry

Provide credentials to access private ECR

There are two options to configure access to AWS-ECR private registry: CloudFormation Template and Configure Manually

### Manual Configuration

This configuration allows you to enter the accountID, accessToken, secretkey and Region. This would allow Lineaje to get access to your organization’s private ECR registry.

For security reasons, Lineaje recommends creating new user with cross account role. Follow the below steps to create a new user:&#x20;

* Go to the AWS console and login using your organization credentials
* Navigate to Identity and Access Management (IAM) and click Users
* Add users, then enter the user name

<figure><img src="/files/HnCEonkCAQ7hnc3eTI0w" alt=""><figcaption></figcaption></figure>

* For the AWS credential type, press Access key - Programmatic access then set permissions. There are two required permissions you will need to set:
  * AmazonEC2ContainerRegistryFullAccess
  * AmazonElasticContainerRegistryPublicFullAccess

<figure><img src="/files/QLk9IYGJBTWvyhWOBhju" alt=""><figcaption></figcaption></figure>

* Skip Tags Tab
* Review Tab

<figure><img src="/files/Yj2FqgwF7jMOYGUafHVI" alt=""><figcaption></figcaption></figure>

* Final tab will provide you the access key id and secret access key

<figure><img src="/files/rrLmhiU3QfzfPRuTo7yN" alt=""><figcaption></figcaption></figure>

### IAM CloudFormation Template​

The CloudFormation Template (CFT) option needs a CFT file to be uploaded.&#x20;

* Download the sample CFT file
* Go to the AWS console and login using your organization credentials

  * Go to the AWS *sign-in page* <https://console.aws.amazon.com/cloudformation&#x20>;
  * Click the buttons Create Stack -> With New Resources

  <figure><img src="/files/iRnpJnXRfX0dibfo8vGh" alt=""><figcaption></figcaption></figure>

  * Leave the Prepare Template setting as-is
    * For Template source select Upload a template file
    * Click Choose file and select the CloudFormation template you downloaded and click Next

  <figure><img src="/files/Q82pevnIl9HoUOqvA2b2" alt=""><figcaption></figcaption></figure>

  * For Stack name use SBOM360-ECR-Permissions-Stack and click Next

  <figure><img src="/files/jB4wCOvrc1JGSKnPtbwN" alt=""><figcaption></figcaption></figure>

  * For Configure Stack Options, it is recommended to use configuring tags, which are key-value pairs that can help you identify your stacks and the resources they create. You will not have to use additional permissions or advanced options so click Next.
  * For Review

    * Scroll down to the bottom of the page and select "I acknowledge that AWS CloudFormation might create IAM resources with custom names."
    * Click Create Stack

    <figure><img src="/files/B7nrd0VSP3nGLrCwwezw" alt=""><figcaption></figcaption></figure>

    * You will be taken to the CloudFormation stack status page, showing the stack creation in progress
      * Click on the Events tab and watch the CloudFormation events as they form the IAM Role
    * Click on the Outputs tab and copy the value of the EcrIntegrationRoleARN key

    <figure><img src="/files/DHSIcSKfn0pwnmhEcQiR" alt=""><figcaption></figcaption></figure>

    * It should look similar to the following key - arn:aws:iam:/sbom360/SBOM360\_ECR\_Role
* Upload the updated CFT in the configure step
* By clicking on Test Connection, the connection will be tested against the credentials


# Configure Google Container Registry

To give access to your organizations’ artifact registry, you will have to enter the project-ID, region and upload the Google Service Account file.

\
To identify the project-ID, follow these steps:

* Go to the GCP console and login using your organization credentials
* Go to the API Console and view the projects list
* Move to the projects list and click Manage all projects
  * NOTE: The Manage all projects space will display all the project names and IDs that you are a member of.
* Navigate to the desired project select the project to display its project-ID


# Configure Docker Hub

To give access to your organizations’ Docker Hub account, you will have to provide the Docker ID and Access Token of the Docker Hub to start this process.&#x20;

<br>


# Configure Generic OCI Registry


# Configure Azure Container Registry

Azure Container Registry supports the standard Docker commands. Azure Container Registry can be configured using "[OCI Compatible Registry](/sbom360/generate-an-sbom/container-image-as-source/private-container-image/configure-generic-oci-registry)".

* Goto [portal.azure.com](https://portal.azure.com.).
* Search to Container Registry
* Navigate to your private Container Registry
* Goto Settings -> Access Keys
* Enter the details -> Registry Name, Login server, Admin user, Username, password, password2

<figure><img src="/files/n8qtFurLKFIB6Rx1vLcr" alt=""><figcaption></figcaption></figure>


# Frequently Asked Questions

### Why do I not see a new project triggered even after clicking on "Save Configuration"?

Project generation has a n optimization to avoid accidental runs of same project configuration. A combination of Project Name, Version, digest of the image is used to generate a unique identifier for each project. A project run is triggered only if the combination of Project Name and Version does not exist.

Note: If its only for testing, the previous project in projects page can be deleted to trigger a new run for the same image.

### How can I change the settings for an existing project?

To change the configure, click on edit configuration.

* Step 1 (Details): Configuration name, description, credentials, repo URLs can be modified.
* Step 2 (Review): Branch/tag can be changed for the existing configuration by going to "Edit Repositories" tab.
* Click on Save Configuration to trigger a new project.


# Existing SBOM As Source

Generate a project by uploading your existing SBOMs in either SPDX or CycloneDX format.

Follow the below steps:

1. Step 1: Project name and version
   1. Enter a name and version for your project.
2. Step 2: Choose format and upload file
   1. Choose the format of your SBOM.
      1. SBOM360 supports both SPDX and CycloneDX files.
      2. Please refer the [support matrix](/sca360-secure-deployment-for-restricted-environments/support-matrix) for  supported versions and formats
   2. Drag and drop or browse to find and enter your desired SBOM file.
   3. CSV uploads are also supported.  Please refer to the following sample file for the supported format.

{% file src="/files/Uhcd8iscswjLhh3Tu39U" %}

1. Step 3: Review
   1. For every file uploaded, [EO 14028](/sbom360/generate-an-sbom/existing-sbom-as-source/eo-14028-checks) check is performed and errors (if any) are displayed
   2. Once the submit is clicked, the SBOM generation kicks off
   3. Please note that the outcome of an SBOM generation with errors in the EO 14028 check will be incomplete.

<figure><img src="/files/x5T83QIedgUJCBRACOEL" alt=""><figcaption></figcaption></figure>


# EO 14028 checks

Minimum elements for an SBOM

### Minimum fields

EO 14028 checks correspond to the minimum elements in an SBOM as described by <https://www.ntia.doc.gov/files/ntia/publications/sbom_minimum_elements_report.pdf>

The table below lists the minimum elements. Some of these fields are at a SBOM level and the others are applicable for each component in the SBOM.

<table><thead><tr><th width="248">Data Field</th><th>Description</th></tr></thead><tbody><tr><td>SBOM Timestamp</td><td>Record of the date and time of the SBOM data creation</td></tr><tr><td>SBOM Author</td><td>The name of the entity that creates the SBOM data for this component</td></tr><tr><td>SBOM dependencies</td><td>Characterizing the relationship that a component X is included in software Y</td></tr><tr><td>Component Name</td><td>Designation assigned to a unit of software defined by the original supplier</td></tr><tr><td>Component Version</td><td>Version assigned to a unit of software defined by the original supplier</td></tr><tr><td>Component Supplier Name</td><td>The name of an entity that creates, defines, and identifies components</td></tr><tr><td>Component Unique Identifiers</td><td>Identifiers that are used to identify a component (like PURL, BomRefId etc)</td></tr></tbody></table>

### Mapping of minimum fields&#x20;

Below is a table mapping the NTIA minimum SBOM fields to SPDX and CycloneDX

|                         | SPDX                                       | CycloneDX                                                        |
| ----------------------- | ------------------------------------------ | ---------------------------------------------------------------- |
| SBOM Timestamp          | (2.9) Created:                             | metadata/timestamp                                               |
| SBOM Author             | (2.8) Creator:                             | metadata/authors/author                                          |
| SBOM dependencies       | (7.1) Relationship: DESCRIBES CONTAINS     | Inherent in nested assembly/subassembly and/or dependency graphs |
| Component Name          | (3.1) PackageName:                         | name                                                             |
| Component Version       | (3.3) PackageVersion:                      | version                                                          |
| Component Supplier Name | (3.5) PackageSupplier:                     | Supplier publisher                                               |
| Component Unique Ids    | (2.5)SPDX Document Namespace (3.2) SPDXID: | bom/serialNumber component/bom-ref                               |


# Manifest file As Source

A manifest file is a configuration file that build tools use to build a project. A manifest file typically carries various build configurations as well as information about dependencies.

Enteprises do not expose the source code. The scm tool that is used for source code management is accessible within the enterprise boundary. So the persona who wants to generate SBOM using Lineaje is often stuck with getting right permissions to provide Lineaje cloud access to the source code. To simplify the SBOM creation, Lineaje supports uploading of the manifest file alone. Doing so will kick start the SBOM generation. All private and third party dependencies referred in the manifest file will remain unresolved as Lineaje does not have access. On the other hand all open source dependencies show up.

The below table lists down the supported manifest files for different build tools. The manifest file typically is found in the root of the source code. Depending on the type of the project, there could be one or more manifest files (root + sub directories).

<table data-header-hidden><thead><tr><th width="92.33333333333331">#</th><th width="323">Build tool</th><th>Manifest file</th></tr></thead><tbody><tr><td>1</td><td>Java / Maven</td><td>pom.xml</td></tr><tr><td>2</td><td>Python / PIP</td><td>requirements.txt</td></tr><tr><td>3</td><td>Rust / Cargo</td><td>Cargo.lock</td></tr><tr><td>4</td><td>Golang / Go Modules</td><td>go.mod</td></tr><tr><td>5</td><td>Yarn</td><td>yarn.lock</td></tr><tr><td>6</td><td>JavaScript / NPM</td><td>package-lock.json</td></tr></tbody></table>


# Binary Files

You can generate an SBOM for your applications using this option.

Currently, the following binary types are supported: **Windows EXE, Windows MSI, Windows DLL, and Android APK**.

Follow the steps below:

* Enter a name and version for your project.
* Drag and drop or browse to select your desired binary file (**.exe, .msi, .dll, .apk**).
* Click the Upload Binary button.
* Once the upload is complete, you will be redirected to your projects page.<br>

<br>


# Dashboard

SBOM360 Dashboard gives metrics across all your projects in your organization.&#x20;

The data in the dashboard can be filtered by two dimensions - organization and time.&#x20;

The data in the dashboard is arranged in 4 logical sections. Each section has a tile with a set of counters followed by charts.

### Risk view

Risk View shows the risks associated with the projects wrt IRL and Attestation

<figure><img src="/files/nwoI1FzAnOjFLnyCMFww" alt=""><figcaption></figcaption></figure>

This Risk View includes:

* Counters for total projects grouped by type (open source, private, third-party, unknown)
* List of Most risky and Least risky projects based on [IRL](/sbom360/projects/irl)
* List of Most risky and Least risky projects based on [Attestation](/sbom360/projects/attestation)
* Trendline graph of the projects based on their IRL scores
* Trendline graph of the projects based on their Attestation scores

### Findings view

Findings view shows the findings associated with the projects.

<figure><img src="/files/BaemIZ5ywU4PNu5HiBFS" alt=""><figcaption></figcaption></figure>

This [Findings](/sbom360/projects/findings) View includes:

* Counters for total findings grouped by staging attribute of the [Gate](/sbom360/policies-and-gates) that created the findings.
* Counters for total findings grouped by the function that created the findings.
* Pie chart of findings by severity
* Bar chart of findings by policy

### Issues view

Issue view shows the issues of components in different dimensions (vulnerability, age, code quality, security posture) grouped by the type of the components (open source, private, third-party, unknown)

<figure><img src="/files/bAESVe6QaSe6Tg2eZ6ut" alt=""><figcaption></figcaption></figure>

### Code commits and Provenance view

Code commits and Provenance view shows the top code commits and countries.

<figure><img src="/files/MVKMSGy938oEcIBC96r1" alt=""><figcaption></figcaption></figure>

<br>

<br>


# Projects

All the SBOMs that you generate show up in the Projects page. Depending on the type of input used to generate the SBOM, SBOM generation may take some time to complete (typically, one minute for small SBOMs and up to 30 min for larger ones).

The status of the SBOM in the Projects page is an indication of the progress in SBOM generation. It starts from Created, then Running and other states and finally show up as Ready for Review.

You can click on the SBOM when it’s in Ready for Review state and explore the SBOM. The data collected for the SBOM is organized into several tabs:

* [Info](/sbom360/projects/info)&#x20;
* [Attestation](/sbom360/projects/attestation)&#x20;
* [Dependencies](/sbom360/projects/dependencies)&#x20;
* [Provenance](/sbom360/projects/provenance)&#x20;
* [Vulnerabilities](/sbom360/projects/vulnerabilities)&#x20;
* [Mitigations](/sbom360/projects/mitigations)&#x20;
* [Security posture](/sbom360/projects/security-posture)&#x20;
* [Code quality](/sbom360/projects/code-quality)&#x20;
* [Suppliers and Licenses](/sbom360/projects/suppliers-and-licenses)&#x20;
* [Findings](/sbom360/projects/findings)&#x20;

You can perform the following actions for a project:

* **Download**

Download a report of your SBOM. The SBOM is currently downloaded as report.json, which is Lineaje's custom format. The report.json has all the attributes that SBOM360 collects using the deep fingerprint engines. This report, by far, has the most comprehensive data associated with the SBOM.

* **Export PDF**

Export the assessment report of your SBOM in PDF format. The assessment report is the summary of the important metadata associated with the SBOM. The report also contains [Lineaje AI ](/sbom360/lineaje-ai)recommendations.

* **Delete**

Delete the SBOM. This action will delete the project and all its components. It will make sure to delete only those components that are unique to the project getting deleted. Any shared components are left in tact.

* **Publish**&#x20;

Publish your SBOM to SBOM360Hub so that it can be shared to your consumers or distributors or resellers.

* Publishing an SBOM Hub creates an immutable copy of the SBOM in SBOM360 Hub
* Publishing an SBOM creates a “Self-Attestation Letter” (SAL) with a list of approvers
* Publishing an SBOM also goes through a mandatory EO14028 check in SBOM360 Hub


# Info

The Info tab gives a summary of the project.. The data is presented as widget. The widgets are clickable.

### Component widget

Component widget gives the metadata associated with the project including

* Project Name
* Project Version
* Project created date
* Project created method (scm/image/spdx)
* Depending on the project creation, additional metadata (e.g. source code repo/tag for scm)
* Project owner - user who created the SBOM

### Findings by severity

Findings by severity table summarizes the findings categorized by severity (critical, high, medium, low). Clicking on the numbers will take you to the search page listing down all components belonging to the respective category.

### Vulnerabilities by severity

Vulnerabilities by severity table summarizes the vulnerabilities by severity (critical, high, medium, low). Clicking on the numbers will take you to the search page listing down all components belonging to the respective category.

### Unique components by classification

Unique components table shows the unique components by classification (open source, private, third party, unknown). Unique component number lists down unique components only once. For a project, it is possible that one component may appear at multiple places in the dependency tree (including direct and transitive dependencies). This table de-duplicates the occurrence and gives the unique component count. Clicking on the numbers will take you to the search page listing down all components belonging to the respective category.

### Lineaje Risk Graph

Lineaje Risk Graph shows the overall risk of the project. The graph gives the quadrant where the overall risk of the project falls. The Y axis represents the aggregated Attestation level (LCAL) of all components in the project and X axis represents the aggregated Risk Level (IRL) of all components in the project.

<figure><img src="/files/4a82iNZ7D7V0C6RBMsAR" alt=""><figcaption></figcaption></figure>

### Issue Count by Vulnerability

This chart gives the number of vulnerabilities against open source, private, third party, unknown components grouped by severity (critical, high, medium, low). Clicking on the numbers will take you to the search page listing down all components belonging to the respective category.

### Findings by policy

Findings by policy gives a visualization of the top policies contributing to findings. Clicking on the numbers will take you to the search page listing down all components belonging to the respective category.

### Components by age

Components by age table lists down the number of components that are older than certain age intervals (>36 months, 24-36 months, 18-24 months, 5-18 months). Clicking on the numbers will take you to the search page listing down all components belonging to the respective category.

### Code quality by classification

This chart gives the number of code quality issues against open source, private, third party components grouped by severity (critical, high, medium, low). Clicking on the numbers will take you to the search page listing down all components belonging to the respective category.

### Security posture by classification

This chart gives the number of security posture issues against open source, private, third party components grouped by severity (critical, high, medium, low). Clicking on the numbers will take you to the search page listing down all components belonging to the respective category.


# Attestation

### What is Attestation?

Lineaje checks for the integrity of every component in the software supply chain of your application. This includes direct and transitive dependencies. The integrity in represented in LCAL (Lineaje Component Attestation Level) in a scale of 0-4.

* LCAL 0: Unknown Component
* LCAL 1: Known Component
* LCAL 2: Attested Component
* LCAL 3: Attested Build & Source
* LCAL 4: Fully Attested

Attested components are those whose integrity check passed along with its provenance thereby further classifying it as a “Known” open-source, private, and/or third-party component. (LCAL 2,3, & 4)

Unattested components are those whose integrity check failed, or provenance could not be verified, thereby further classifying it as an “Unknown” component. (LCAL 0 & 1)

### How is attestation calculated?

SBOM360 validates software integrity with Lineaje's Deep Fingerprinting Technology and assigns it an attestation status for each component. Each attestation level is based on data found with Deep Fingerprinting Technology.

* LCAL 0: Unknown Component
  * Component could not be resolved
  * Not EO14028 compliant
* LCAL 1: Known Component
  * Component name and PURL are identified and attested
  * Package available at PURL location
  * Component fingerprints do not match
  * Not EO14028 compliant
* LCAL 2: Attested Component
  * Component name and PURL are identified and attested
  * Package available at PURL location
  * Fingerprints match
  * EO14028 compliant with the attested components
* LCAL 3: Attested Build & Source
  * Component package is Attested
  * Package source exists
  * Attested to be built from the source
  * EO14028 compliant with attested software supply chain and SBOM
* LCAL 4: Fully Attested
  * Component package and source are untampered and malware free
  * Attestation shows no malicious code nor tamper in or between original source and built output
  * Compatible with builds previously produced
  * EO14028 compliant with untampered, attested supply chain, and SBOM

Attestation for a project is calculated based on the **mean** value of attestation scores of all components.

### Understanding Attestation

<figure><img src="/files/uGJ8gdWazeYzld7RMaSX" alt=""><figcaption></figcaption></figure>

* Count of components with their attestation level is displayed towards left, along with the category of the components (open-source, private, third-party, unknown).
* Each tile is clickable which will list down the components applicable to that filter in a table view. The details will list the component name, version and a capsule for attestation level.
* By clicking the attestation level capsule, next level details will be shown as below.

<figure><img src="/files/PhaaEBCFz0V6KmVDPYni" alt=""><figcaption></figcaption></figure>

<br>


# IRL

### What is LIRL?

LIRL stands for Lineaje Inherent Risk Score. The inherent risk is represented as LIRL in a scale of 0-10

* ZIRL 0: Zero IRL. Zero risk with this component/project. This is the preferred IRL.
* LIRL : Low IRL. Risk score falls between 0.1 to 3.9. The component/project carries a lower risk
* MIRL: Medium IRL. Risk score falls between 4.0 to 6.9. The component/project carries a medium risk
* HIRL: High IRL. Risk score falls between 7.0 to 8.9. The component/project carries a high risk
* CIRL 4: Critical IRL. Risk score falls between 9.0 to 10.0. The component/project carries critical risk

### How is IRL calculated?

IRL is calculated based on 4 factors - age, vulnerability score, code quality score, security posture score. IRL is calculated as a weighted average.

&#x20;                                   **IRL of project = mean(components IRL in dependency tree)**

<table data-header-hidden><thead><tr><th width="165"></th><th width="150"></th><th></th></tr></thead><tbody><tr><td><strong>IRL contributor</strong></td><td><strong>Weightage</strong></td><td><strong>Description</strong></td></tr><tr><td>Vulnerability</td><td>80% weightage</td><td><ul><li>3.0 score if atleast one exploitable vulnerability found</li><li>2.0 score if atleast one critical vulnerability found</li><li>1.5 score if atleast one high vulnerability found</li><li>1.0 score if atleast one medium vulnerability found</li><li>0.5 score if atleast one low vulnerability found</li></ul></td></tr><tr><td>Unmaintained Component</td><td>10% weightage</td><td><ul><li>1.0 score based on maintained/unmaintained (0.0 or 1.0)</li></ul></td></tr><tr><td>Security Posture</td><td>5% weightage</td><td><ul><li>0.5 rating based on atleast one security posture issue (0.0 or 0.5)</li></ul></td></tr><tr><td>Code Quality</td><td>5% weightage</td><td><ul><li>0.5 rating based on atleast one Code Quality issue (0.0 or 0.5)</li></ul></td></tr></tbody></table>


# Dependencies

### What are Dependencies?

Dependencies are the components that are required for your application to run.

The dependencies can be open-source, third-party or closed-source(private). Dependencies can be classified as direct and transitive dependencies.

### Understanding Dependencies

<figure><img src="/files/PgnfRcGcIycsAUUwb9as" alt=""><figcaption></figcaption></figure>

* Count of components are displayed towards left, along with the category of the components (open-source, private, third-party, unknown).
* The dependency count is displayed towards the right, giving the number of direct dependencies, number of transitive dependencies, depth of the dependency tree.
* Each tile is clickable which will list down the components applicable to that filter in a table view. The details will list the component name, version, classification and a capsule for dependency counts.
* By clicking the dependency count capsule, next level details are shown as below

<figure><img src="/files/SKzkM0OuPpjJIDd38aYb" alt=""><figcaption></figcaption></figure>


# Provenance

### What is Provenance?

Provenance refers to the author, region of commits on your source code.

It illustrates the history of your code so you can better understand the origins and trustworthiness of the software.

### Understanding Provenance

<figure><img src="/files/K6BYe3iMW9MkCfAquSM5" alt=""><figcaption></figcaption></figure>

* Count of components that are with provenance information is displayed towards left, along with the category of the components (open-source, private, third-party, unknown).
* The top countries contributing to the code commits is displayed in the middle
* The top authors contributing code is listed towards the right.
* Each tile is clickable which will list down the components applicable to that filter in a table view. The details will list the component name, version, supplier, a capsule for contributors and a capsule for countries.
* By clicking the capsule, next level details will be shown.
* By clicking on any row, the sidesheet shows up.

<br>

<br>


# Vulnerabilities

### What is Vulnerability?

A security flaw, glitch, or weakness found in software code that could be exploited by an attacker (threat source).

To understand the overall risk of a software, it is important to understand the vulnerabilities of the direct as well as the transitive dependencies.

### Understanding Vulnerabilities

<figure><img src="/files/ppjHkNxPDyB1m23FLhQ4" alt=""><figcaption></figcaption></figure>

* Count of components that are vulnerable is displayed towards left, along with the category of the components (open-source, private, third-party, unknown).
* The vulnerability count is displayed towards the right, grouped by severity (critical, high, medium, low).
* Each tile is clickable which will list down the components applicable to that filter in a table view. The details will list the component name, version, total vulnerabilities and a capsule for vulnerabilities details.
* By clicking the vulnerabilities capsule, next level details will be shown as below.
* By clicking on any row, the sidesheet shows up as shown below.

<figure><img src="/files/cEFwwHliJjKrD2wf96w9" alt=""><figcaption></figcaption></figure>

<br>

<br>


# Mitigations

Mitigate your vulnerabilities

### What is a mitigation?

A mitigation in this context refers to vulnerability mitigation. Vulnerability mitigation is the process of reducing or eliminating the risk associated with a security vulnerability.&#x20;

A software may often contain vulnerabilities of various severity. One way to mitigate these vulnerabilities is to fix all of them. Another way of mitigating these vulnerabilities is to analyze the risk associated with the vulnerabilities in the context of the application and publishing a [CSAF](#what-is-csaf).&#x20;

The vulnerability count after applying the mitigations becomes the effective vulnerability count. This is shown by the Lineaje risk graph in the [Info tab](/sbom360/projects/info). The black start represents the project risk with the actual vulnerabilities present. The blue star represents the project risk re-evaluated after applying the vulnerability mitigations.

<figure><img src="/files/N3hTMRKgV0gdaMlefGwb" alt=""><figcaption></figcaption></figure>

### Understanding mitigation

The mitigations tab lists all the vulnerability mitigations that are uploaded in the form of [CSAF](#what-is-csaf).&#x20;

<figure><img src="/files/hwliNRs3SUWCSOZ3cVoa" alt=""><figcaption></figcaption></figure>

* Count of components that are mitigated is displayed towards left, along with the category of the components (open-source, private, third-party, unknown).
* The mitigation count is displayed towards the right, grouped by severity (critical, high, medium, low).
* Each tile is clickable which will list down the components applicable to that filter in a table view. The details will list the component name, version, total vulnerabilities and a capsule for vulnerabilities details.
* By clicking the vulnerabilities capsule, next level details will be shown as below.&#x20;
* By clicking on any row, the sidesheet shows up as shown below. There is a section showing the mitigation related information - mitigation origin, mitigation category, mitigation details. This information is sourced from the [CSAF ](#what-is-csaf)that was uploaded.

<figure><img src="/files/TjRYRBf3cIVY56I0ItlB" alt=""><figcaption></figcaption></figure>

### What is CSAF?

CSAF stands for Common Security Advisory Framework. Common Security Advisory Framework (CSAF) is a language to exchange Security Advisories. It plays a crucial role in the cybersecurity arena since it allows stakeholders to automate the creation and consumption of security vulnerability information and remediation. More details can be found here.

<https://oasis-open.github.io/csaf-documentation/>

<https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html>

### How can I upload CSAF?

CSAF upload is available under Integrations from the left navigation bar. A CSAF document is a json that describes the mitigations for the vulnerabilities and the products that are applicable for. You can refer a sample CSAF

<figure><img src="/files/AP8J2yUA4vAidkgdeaC9" alt=""><figcaption></figcaption></figure>

A sample CSAF document looks something like this

<details>

<summary>Sample CSAF</summary>

```json
{
    "document": {
        "title": "Lineaje generated security advisory for calendro.fr.nf",
        "csaf_version": "2.0",
        "category": "csaf_security_advisory",
        "lang": "en",
        "notes": [
            {
                "title": "Legal Disclaimer",
                "category": "legal_disclaimer",
                "text": "THIS DOCUMENT IS PROVIDED ON AN \"AS IS\" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. LINEAJE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.\n\nA standalone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy and may lack important information or contain factual errors."
            }
        ],
        "publisher": {
            "category": [
                "translator"
            ],
            "issuing_authority": [
                "Lineaje Security Advisory"
            ],
            "name": [
                "Lineaje Inc."
            ],
            "namespace": "https://www.lineaje.com"
        },
        "tracking": {
            "id": "lineaje-78f5d464-30db-57b4-9253-f1fe21dd67ac",
            "generator": {
                "engine": {
                    "name": "LINEAJE INC"
                },
                "date": "2024-05-06T22:09:53.873514"
            }
        }
    },
    "product_tree": {
        "full_product_names": [
            {
                "name": "apache-zookeeper__3.7.1",
                "product_id": "apache-zookeeper__3.7.1"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2023-44981",
            "title": "CVE-2023-44981",
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "baseScore": "9.1",
                        "exploitabilityScore": "3.9",
                        "impactScore": "5.2",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
                    }
                }
            ],
            "references": [
                {
                    "url": "https://lists.apache.org/thread/wf0yrk84dg1942z1o74kd8nycg6pgm5b"
                },
                {
                    "url": "http://www.openwall.com/lists/oss-security/2023/10/11/4"
                },
                {
                    "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00029.html"
                },
                {
                    "url": "https://www.debian.org/security/2023/dsa-5544"
                },
                {
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44981"
                }
            ],
            "product_status": {
                "fixed": [
                    "apache-zookeeper__3.7.1"
                ]
            }
        },
        {
            "cve": "CVE-2022-2048",
            "title": "CVE-2022-2048",
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "baseScore": "7.5",
                        "exploitabilityScore": "3.9",
                        "impactScore": "3.6",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                    }
                }
            ],
            "references": [
                {
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2048"
                },
                {
                    "url": "https://github.com/eclipse/jetty.project/security/advisories/GHSA-wgmr-mf83-7x4j"
                },
                {
                    "url": "http://www.openwall.com/lists/oss-security/2022/09/09/2"
                },
                {
                    "url": "https://lists.debian.org/debian-lts-announce/2022/08/msg00011.html"
                },
                {
                    "url": "https://www.debian.org/security/2022/dsa-5198"
                },
                {
                    "url": "https://security.netapp.com/advisory/ntap-20220901-0006/"
                }
            ],
            "product_status": {
                "fixed": [
                    "apache-zookeeper__3.7.1"
                ]
            }
        }
     ]
}
```

</details>

### What happens when I upload a CSAF?

Lineaje platform will re-calculate the overall risk score of your application based on the mitigations provided by the CSAF document. The [IRL](/sbom360/projects/irl) gets recalculated the Lineaje Risk Graph shows a new blue star in the new quadrant.

A CSAF upload will result in the re-assessment of all projects across the different Lineaje products (SBOM360, SBOM360Hub, OSM). The re-assessment assumes the project names to match with the project names shown in the projects page(from left navigation bar). The project name and version should be separated by "\_\_" in the CSAF document.&#x20;

For apache-zookeeper:3.7.1, here is a sample from CSAF document

```json
       "full_product_names": [
            {
                "name": "apache-zookeeper__3.7.1",
                "product_id": "apache-zookeeper__3.7.1"
            }
        ]
```

```json
"vulnerabilities": [
    {
        "cve": "CVE-2023-44981",
        "title": "CVE-2023-44981",
        "scores": [...],
        "product_status": {
            "fixed": [
                "apache-zookeeper__3.7.1"
            ]
        }
    }
]
```

### Can I generate a CSAF?

Lineaje platform provides you options to generate a CSAF document.

* If mitigations were applied to projects, those status will be included in the generated CSAF document
* If no mitigations were applied, then Lineaje platform makes the status of each project as "under\_investigation". Once the vulnerability analysis is done, this CSAF document can be updated and then uploaded back in Lineaje to calculate the new risk of the projects.

CSAF document can be generated for a project or for a vulnerability or for a SKU(list of associated projects) etc.

Projects page (from left navigation bar) provides an option under "Action" menu to download a CSAF for the project

<figure><img src="/files/kahqzw8aSuqbSyqGQCFI" alt=""><figcaption></figcaption></figure>

Serach page (from left navigation bar) provides an option to download CSAF. This option is very flexible. A CSAF can be generated for a CVE or for a project or for an organization or for the entire company. Here is an example to generate CSAF for a CVE

<figure><img src="/files/yjQdXvWSCBICYV27fgyy" alt=""><figcaption></figcaption></figure>


# Security Posture

### What is Security Posture?

Security posture is calculated by running a set of checks on the source code of each component.

This includes direct and transitive dependencies.

List of Security Posture Checks

* Branch Protection: Are the default and release branches protected with GitHub's branch protection settings?
* Pinned Dependencies: Has the project declared and pinned its dependencies?
* Dangerous Workflow: Does the project's GitHub Action workflows avoid dangerous patterns?
* Static Application Security Testing (SAST): Does the project use static code analysis?
* Dependency Update Tool: Does the project use a dependency update tool?
* Security Policy: Has the project published a security policy?
* Fuzzing: Does the project use fuzzing in OSS-Fuzz?
* Token Permissions: Is the project following the principle of least privilege?
* Packaging: Has the project been published as a package that others can easily download, install, update, and uninstall?
* Webhooks: Are the webhooks defined in the repository token configured?

### Understanding Security Posture

<figure><img src="/files/Dn9OHQQ92L8pca49jJ1P" alt=""><figcaption></figcaption></figure>

* Count of components that have security posture issues is displayed towards left, along with the category of the components (open-source, private, third-party, unknown).
* The security posture issue count is displayed towards the right, grouped by severity (critical, high, medium, low).
* Each tile is clickable which will list down the components applicable to that filter in a table view. The details will list the component name, version and a capsule for security posture checks.
* By clicking the security posture checks capsule, next level details will be shown as below.
* By clicking on any row, the sidesheet shows up as shown below.

<figure><img src="/files/Xuu0OEGfmzDHArSR1G9n" alt=""><figcaption></figcaption></figure>

<br>

<br>


# Code Quality

### What is Code Quality?

Code quality is calculated by running a set of checks on the source code of each component.

This includes direct and transitive dependencies.

List of Code Quality Checks

* Binary Artifacts: Has the project generated executable (binary) artifacts in the source repository?
* CII Best Practices: Does the project have a CII Best Practices badge?
* Fuzzing: Does the project use fuzzing in OSS-Fuzz?
* Pinned Dependencies: Has the project declared and pinned its dependencies?
* CI Tests: Does the project run tests before pull requests are merged?
* Code Review: Does the project require a code review before pull/merge requests are assimilated?
* Maintained: Is the project actively maintained?

### Understanding Code Quality

<figure><img src="/files/PDcUZQYtlcE4Uo5i3qLx" alt=""><figcaption></figcaption></figure>

* Count of components that have code quality issues is displayed towards left, along with the category of the components (open-source, private, third-party, unknown).
* The code quality issue count is displayed towards the right, grouped by severity (critical, high, medium, low).
* Each tile is clickable which will list down the components applicable to that filter in a table view. The details will list the component name, version and a capsule for code quality checks.
* By clicking the code quality checks capsule, next level details will be shown as below.
* By clicking on any row, the sidesheet shows up as shown below.

<figure><img src="/files/BT7Q4Ihn3UcIyhniyRFB" alt=""><figcaption></figcaption></figure>

<br>

<br>


# Suppliers & Licenses

SBOM360 analyses the software suppliers, licenses, and presents them all within your SBOM project at both the SBOM and component level. To ensure supply chain security, it is important for you to carefully vet your suppliers and conduct thorough security assessments of the software they provide. Licensing information can helps ensure that the software is compliant with open-source, private, and third-party licensing requirements.

### Understanding Suppliers & Licenses

<figure><img src="/files/TX9DvnTqqLNxOiAP1QqA" alt=""><figcaption></figcaption></figure>

Total Suppliers: List all suppliers in the current SBOM. This gives the metadata for the supplier like Name, Organization, Website, number of components by this supplier in this SBOM, number of components by this supplier across all your SBOMs in your organization.

Total Project Licenses: List unique license category and license name. This gives the metadata like license category, license name, license version, license URL.

Total unique Authors: List the authors responsible for code commits. This gives the metadata like contributor name, email, number of commits.

Total Supplier Components: All components in the current project that are contributed by the suppliers.

<br>

<br>


# Findings

### What are Findings?

Findings of an project are the results of policy evaluation.

There could be multiple policies attached to an project and there would as many findings associated.

Policies get associated with a project via [Gates](/sbom360/policies-and-gates). A gate can be defined at an organization level. All policies associated with the gate will be run against the projects in that organization.

### Understanding Findings

<figure><img src="/files/de9Vo3l3ySItAyuSFe9A" alt=""><figcaption></figcaption></figure>

* All components that are flagged by the policy evaluation are displayed towards left, along with the category of the components (open-source, private, third-party, unknown).
* The findings are displayed towards the right, categorized as critical, high, medium, low.
* The severity associated with a policy decides the severity of the finding. A policy marked as critical, when check fails, will generate a critical severity finding.&#x20;
* Each tile is clickable which will list down the components applicable to that filter in a table view. The details will list the policy name that triggered this finding, the gate associated with the finding, severity of the finding.

<br>

<br>


# Search

Search page allows you to search components meeting specific criteria.&#x20;

<figure><img src="/files/7uLntteGueenOXoNwKHx" alt=""><figcaption></figcaption></figure>

### **How to search for components?**

Two types of search queries are supported

#### **Search powered by AI**

Search powered by AI accepts English query strings and gives the results.IN the Search bar, the default option is always the AI powered search.

Serach queries can be a complex query involving multiple conditions.

Few examples of search queries are:

* Components with Critical or High Vulnerabilities that are exploitable
* Components released after Ukraine war
* Components with license MIT or Apache 2.0
* OSS Components with Critical or High Vulnerabilities

#### **Search powered by GraphQL (GQL)**

The search bar supports a switch from prompt (English query) to GQL. A GQL provides a way to fine tune the results of a query.&#x20;

GQL for the AI powered query - "Components with critical vulnerabilities" is shown below

```
    query ComponentSearch(
      $tenantId: String!
      $scope:String
      $sort: JSON
      $aggregation: JSON
      $page: Int
      $queryString: String
      $queryType: String 
      $limit: Int
    ) {
      componentSearch: componentSearchAdHocV2(
        tenantId: $tenantId
        scope:$scope
        aggregation: $aggregation
        sort: $sort
        page: $page
        queryType: $queryType
        limit: $limit
        queryString:$queryString
      )
    }  
```

### **Scope of search**

The scope of search determines the result. There are two scopes supported:

#### **My projects**

My projects scope allows you to search all components that are used within your projects. These components can be open source, private, third party and any unknown components. The search is performed across all the projects (SBOMs) created in the tenant across all organizations. The search is restricted to your tenant's data.

#### Open Source

Open Source scope allows you to search for open source components. Lineaje cloud runs a crawler that creates SBOMs for open source components. The search is performed on the open source components database that is shared across all tenants. This search does not include any private projects.

### Viewing search results

There are two views provided in search results

#### Table view

The table view lists down the results in a table view. The table view lists down columns that are determined, best match, based on the query context.

The column option can be used to view additional columns. The filters can be used to query for specific data.

Clicking on any row in the table takes you to the corresponding component view.

#### Git-Card view

The git-card view lists down the results in a card view. The git-card view lists down data that are determined, best match, based on the query context.

The column option can be used to view additional columns. The filters can be used to query for specific data.

### Save Search

A search can be saved. The saved search will be listed in "Saved List". The saved search will be visible for all users in the tenant.

### Export search as csv

The search results can be exported as a csv. The search results may vary from few to several hundred or thousands. So exporting search is an asynchronous call. A background job gathers the results, prepares a csv and notifies in the notification icon (bell icon) as well as an email is sent when the data is ready.


# Policies and Gates

### **What is a Gate?**

A Gate is a group of policies (checks). Gate can be applied at an organization level. All SBOMs generated in an organization are evaluated against the organization's gate(s) to generate findings.

Gate supports inheritence. A gate associated with a root org will also be applied to child orgs.

A Gate is associated with:

* A set of policies
* Stage, which can be "As Sourced", "As Built", "As Deployed", "As Shipped". A stage represents the stage of the build pipeline where the gate is applied.
* Function Type, which can be any one of the valid [function](/getting-started/organization-and-user-management). The function type represents who can modify the gate once the gate is created. A combination of organization and function type decides who can modify the gate.
* Intergration Type, which can be "scm", "image", "sbom upload". The integration type represents the type of integration the gate is associated with.

### **Why is a Gate important?**

A gate provides a mechanism for organizations to evaluate all software that are produced and/or consumed against a set of policies and get visibility into the various dimensions like vulnerabilities, risk level, provenance, license types, code quality, security posture etc.

Lets look at an example. Lets say, CISO of a company wants to understand the risks of the software that is getting shipped. The CISO would create one or more gates as shown below:

* Risky vulnerable components gate
* Risky component Assessment gate
* Risky License Usage gate
* Risky code commits gate

The CISO then delegates the creation of policies (checks) for these gates to a Software Procurement manager, Legal group, Release manager. The gates can then be assigned to the root organization in which case these gates will be applied to all child organizations and assessment happens on all the SBOMs generated.

Now the CISO can see a dashboard which summarizes the policy evaluation results of all the SBOMs

<figure><img src="/files/iY3EnDbQDn0agzafN62r" alt=""><figcaption></figcaption></figure>

Gate also defines the visibility of the SBOMs, Gates and hence policies. Please refer [organization example](/getting-started/organization-and-user-management/organization-example) to understand more.

### **What is a policy?**

A policy is a check that is performed on an SBOM. A search string (english query) can be saved as a policy. The english query can be a combination of AND, OR conditions. A policy can evaluate any dimension of an SBOM - vulnerabilities, security posture, age of components etc.&#x20;

### **How to create policy?**

Lineaje "Save Search as policy" can be used to create a policy.  From the search page, any search query can be saved. A few examples of policies:

A search query "Components with Critical or High Vulnerabilities" can become Risky Vulnerability Policy&#x20;

A search query "Components with Critical or High Vulnerabilities that are exploitable" can become Exploitable Vulnerability Policy

A search query "Components with code quality issues related to Binary Artifacts" can become Source Repo Misconfiguration Policy


# Lineaje AI

Lineaje is powered by AI in [Search ](/sbom360/search)and BOMbot.

### BOMbot

BOMbot is a chatbot that can help answering questions about your projects.

<figure><img src="/files/7zkxzekoIbLfdENjxTs6" alt=""><figcaption></figcaption></figure>

With Lineaje BOMbot, you can chat, view the data for your question, ask for recommendation.

#### Chat

BOMbot can answer questions about your projects like

* What are the critical vulnerabilities in the project?
* How many critical vulnerabilities are present in the project that have available fixes?
* Summarize the high severity vulnerabilities that have patches available in my SBOM
* Show the exploitable vulnerabilities in the project
* Which exploitable vulnerabilities in the project's dependencies have fixes available?
* Show me vulnerable components that are older than 36 months
* Show we critical vulnerabilities that have code issues

#### View Details

Along with the answers to your question, the BOMbot also gives all relevant data associated with the answer available under "View Details" link. Clicking on the link opens up a table view that shows all the relevant data.

#### Recommendation

You can ask BOMbot recommendations in fixing the issues. An e.g. recommendation is shown below

> Query : "*Show me the recommendation for fixing vulnerabilities*"
>
> "*Recommendation*
>
> *There are a total of 88 components, with 17 direct dependencies and 71 transitive dependencies. The direct dependencies consist of 17 OSS components, while the transitive dependencies consist of 71 OSS components.*
>
> *The total vulnerability count is 70, with 38 direct vulnerabilities and 32 transitive vulnerabilities. The 38 direct vulnerabilities consist of 38 OSS vulnerabilities.*
>
> *Of the direct dependency vulnerabilities, 3 components have vulnerabilities with fixes available, while 14 components have vulnerabilities without fixes available. There are 4 direct dependency vulnerabilities that have fixes available.*
>
> ### *Here are some of the least effort changes that can be applied*
>
> *pkg:maven/org.apache.rocketmq/rocketmq-broker\@5.0.0 to pkg:maven/org.apache.rocketmq/rocketmq-broker\@5.1.1*\
> *pkg:maven/org.apache.rocketmq/rocketmq-controller\@5.0.0 to pkg:maven/org.apache.rocketmq/rocketmq-controller\@5.1.1*\
> *pkg:maven/org.apache.rocketmq/rocketmq-namesrv\@5.0.0 to pkg:maven/org.apache.rocketmq/rocketmq-namesrv\@5.1.2*
>
> *Since there are no vulnerabilities impacted by the least effort changes, the IRL score of 7.13 does not change for this scenario.*
>
> ### *Here are some of the optimal effort changes that can be applied*
>
> *pkg:maven/org.apache.rocketmq/rocketmq-broker\@5.0.0 to pkg:maven/org.apache.rocketmq/rocketmq-broker\@5.1.1*\
> *pkg:maven/org.apache.rocketmq/rocketmq-controller\@5.0.0 to pkg:maven/org.apache.rocketmq/rocketmq-controller\@5.1.1*\
> *pkg:maven/org.apache.rocketmq/rocketmq-namesrv\@5.0.0 to pkg:maven/org.apache.rocketmq/rocketmq-namesrv\@5.1.2*
>
> *Applying the optimal effort changes reduces the total vulnerability count from 70 to 21, and the IRL score improves from 7.13 to 6.35.*"


# AI Plan and AI Remediate

Select a Lineaje AI generated plan and remediate your findings

## Understanding AI Plan and AI Remediation

[Gates and policies](/sbom360/policies-and-gates) that are applied to an org results in creation of [findings](/sbom360/projects/findings). Findings are nothing but policy violations.  Lineaje uses AI to create various plans and suggest remediations. Once a plan is selected, JIRA tickets are raised for all the components in the plan and AI recommendation is listed for remediation.

### What is AI generated plan?

Lineaje uses AI to generate 3 different plans as described below.

#### **Compatible Update**

The "Compatible Update Plan" focuses on guiding you through the application of update patches that are safe and compatible. It's akin to an immediate update plan swiftly addressing vulnerabilities without introducing significant changes or disruption to your system.

&#x20;**Minor Update**

The "Minor Update Plan" is ideal for software minor updates. While it suggests changes that enhances security and functionality, some testing is recommended to ensure seamless operation post-update. This plan strikes a balance between addressing vulnerabilities and maintaining system stability.

&#x20;**Major Update**

The "Major Update Plan" addresses all unfixed vulnerabilities and issues related to unmaintained components. It involves thorough remediation efforts, including outsourcing of inner-sourcing OSS component fixes. This plan ensures comprehensive security coverage by addressing underlying OSS dependency issues.

### What happens when a plan is selected?

When a plan is selected, a JIRA ticket is created with the finding details and AI recommendation. It is mandatory to [configure JIRA ](/sbom360/ai-plan-and-ai-remediate/jira-integration)to select a plan.

* If the plan selected is either Compatible Update or Minor Update, then the components under the plan are added to the configured JIRA
* If the plan selected is "Major Update", then the&#x20;
  * components that can be fixed locally are added to the configured JIRA project. This typically include private components, third-party components, open source components with known fixes.
  * open source components without fixes are eligible for outsourcing for fixes and are added to an external JIRA project.

For the configured JIRA project, a JIRA EPIC is created for each project.

<figure><img src="/files/klIHbbVHplZNNv8ieEuU" alt=""><figcaption></figcaption></figure>

* The EPIC summary gives the info of the project name, version, project id
* All components that are part of the plan is represented by a story under the epic
* The epic will have label - "Lineaje AI"

<figure><img src="/files/vOeXUuKCyJBIeDP0DCbf" alt=""><figcaption></figcaption></figure>

* Each story represents one component that is part of the plan
* Each story gives a summary of the project name, version, project id and component name: version
* Each story provides a summary and an action:
  * Plan selected
  * Component details
  * Classification of the component
  * Policies contributing to the current finding
  * AI Recommendation
  * Details about the vulnerabilities present in the component

### Where can I see the projects that are part of AI Remediation?

The AI Plan & AI Remediate on the left navigation bar shows the list of projects under plan and remediate

<figure><img src="/files/G13vVu0ypTXIM5cUNnVP" alt=""><figcaption></figcaption></figure>

* AI Plan tab lists the projects that are eligibale for AI Plan. Any project that has at least one Vulnerability Finding is eligible for AI Plan.
* AI Remediate tab lists the projects that are part of AI Remediate plan.

### AI Plan and Remediate example

For e.g., below is a project for Atlassian velocity (atlassian-apache-velocity-1.6.4-atlassian, <https://bitbucket.org/atlassian/apache-velocity-1.6.4-atlassian>)

<figure><img src="/files/rOYAvRge4GxnYeJ7Our8" alt=""><figcaption></figcaption></figure>

With all the gates and policies applied to this org and hence the project, there are 3 components and a total of 10 findings. Out of 10 findings, 9 of them are created by vulnerability related policies and the remaining one is created by software integrity related policy.

A new option "Vulnerability Findings" is shown towards the top right with a "Create Plan" included. This option can be used to exercise AI Plan and AI Remediate feature.

### What is a Vulnerability Finding?

Any finding (policy violation) that resulted due to a check against the vulnerability of a component is shown as Vulnerability Finding.

Findings can be generated due to a policy checking for violations against vulnerability or attestation (LACL) or Risk Level (IRL) or Code Quality Issues or Security Posture Issues. If a finding is created by a policy, checking for vulnerability of a component, it is shown as vulnerability finding.

### Preview plans

Clicking on "Create Plan" in the findings tab or on the "AI Plan and AI Remediate" tab generates the preview of the available plans.

<figure><img src="/files/Ush1clacEXUZT8yMayjC" alt=""><figcaption></figcaption></figure>

* Each plan shows the summary of the plan
* Each plan shows a list of (top 10) components and their recommended upgrades.
* A "View Details" option lists down all components that can be remediated as part of the plan

<figure><img src="/files/RroFjXnqumPgxV566sGg" alt=""><figcaption></figcaption></figure>

* By default all components are selected to be part of remediation.
* You can exclude specific components that should not be part of the plan
* Click on "Save Plan" to save the changes
* Click on "Return to AI Plans"

<figure><img src="/files/Fg4rMdrLI2HFLDwy3h1u" alt=""><figcaption></figcaption></figure>

### Select a plan

* Click on "Select Plan" to select the plan.
* Note that a JIRA integration is a must for the "Select Plan" to appear
* On applying the plan, JIRA tickets will be created automatically
* Lineaje periodically checks for the changes in the tickets states and reflects the status.

<figure><img src="/files/H5EiskIcmddTE1entjHn" alt=""><figcaption></figcaption></figure>

###


# JIRA Integration

Integrate your JIRA project to create tickets for AI Remediation

JIRA can be configured under Integrations from left navigation bar

<figure><img src="/files/ajklYF65B9KrDICKIMtd" alt=""><figcaption></figcaption></figure>

Configure JIRA

Configuring JIRA is a two step process

Step 1:

<figure><img src="/files/rB8EdpkRZ7d08kWkl80S" alt=""><figcaption></figcaption></figure>

* Enter the configuration name
* Enter the JIRA URL
* Enter the JIRA token
* Enter the Username. This will be the "Reporter" username
* Enter the default assignee against which the tickets will be raised
* Enter a description

Step 2:

<figure><img src="/files/63q5ySGzC7KHH6vIqzJh" alt=""><figcaption></figcaption></figure>

* Choose the project against which Lineaje AI remediation tickets will be raised
* Save the JIRA configuration


# SBOM360 Hub

SBOM360 Hub is a platform to exchange SBOMs. SBOM360 Hub enables your organization to share your private SBOMs with your customers/distributors/resellers and request SBOMs from other suppliers.

SBOM360 Hub maintains an immutable copy of the SBOM. This enables all your customers to see the same data for your products/SKU irrespective of how many times its shared.

Here are things that you can use SBOM360 Hub for

* Upload an existing SBOM generated by any SCA tool
* Verify whether your SBOM is EO14028 compliant
* Share SBOM with your customers, distributors, resellers
* Request an SBOM from a supplier
* Assess the externally uploaded SBOM in SBOM360 and view you SBOM
* Download assessment report for your SBOM

<br>


# My Products

### What is the SBOMs Tab?

Your SBOM360 Hub account will open to the homepage, titled SBOMs. This is an organization wide SBOM database. Whenever SBOMs are published by your company, they will appear here upon approval.

### SBOMs Tab Features

This page has the features:

* Add to My SBOMs
  * Select the box to the left of your desired SBOM in the SBOMs tab
  * Go to the right of the screen and click Add to My SBOMs
  * Confirm that the SBOM has been added
* Upload
  * Jump to the guide on uploading SBOMs to SBOM360 Hub
* Share
  * Jump to the guide on sharing SBOMs with other users
* Request
  * Jump to the guide on requesting full access to SBOM data
* Download and Delete
  * Jump to the guides on downloading SBOMs to your computer and deleting SBOMs from SBOM360 Hub
* Details and View Details
  * Jump to the guides on reviewing the basic and elaborate SBOM details
* Assess & Export
  * Jump to the guide on creating an SBOM assessment report and exporting it to a PDF

<br>

<br>


# My SBOMS

### What is the My SBOMs Tab?

This tab will contain all the SBOMs that you have published, added to your My SBOMs list, and/or that have been shared with you. All your published projects will automatically appear in My SBOMs once they are completely and correctly uploaded to SBOM360.

### Adding SBOMs

To add an SBOM to your My SBOMs tab:

* Select the box to the left of your desired SBOM in the SBOMs tab
* Go to the right of the screen and click Add to My SBOMs
* Confirm that the SBOM has been added
  * You may still need to request access to this SBOM if you do not own it or if the owner has not shared it with you

If an SBOM has not been shared with you already, you must either contact the SBOM owner directly or proceed through the requesting access process in SBOM360 Hub (Lineaje suggests the requesting process to optimize your organization’s distribution chain). Go to the SBOM Request instructions for more on this process.

<br>

<br>


# Find & Review SBOMs

Easily navigate and study published SBOMs.

### &#x20;SBOM360 Hub Search

To search for more specific SBOMs or users, use the hub search bar within any of the tabs.

For the SBOMs page:

* Type the SBOM name, version, SKU, and/or supplier
* Press Filter
* To look for SBOMs that you do not have access to:
  * Check the not in My SBOMs box to the right of the search bar
* Select your desired SBOM or:
  * Click either SBOM name, SKU, or supplier title above the list of SBOMs. This will reorganize the whole list top to bottom according to the selected specification

For the My SBOMs tab, you will go through the same process as above. The only difference is that it will only filter through the SBOMs already available in your My SBOMs tab.

All the search bars in the other tabs in SBOM360 Hub (Supplier, Customer, Distributor, Resellers) will search for users. In the search bar:

* Type the user’s name, company website, and/or primary email
* Press Filter
* Select a user or:
  * Click either the name, company website, or primary email title above the list of SBOMs. This will reorganize the whole list top to bottom according to the selected specification

### Review

The main purpose of SBOM360 Hub is to provide quick and easy access to SBOM details. This makes reviewing SBOMs and software much simpler. Steps to view project information in SBOM360 Hub include:

* Click on the project name to open a short project overview
* Go to the top-right corner of the overview and press View Details
* Read through the Lineaje SBOM overview, which is the total findings for each aspect of the SBOM. Or select specific components to open Lineaje Component Attestation Level (LCAL) to see the details of that single component


# Manage Your Repository

Walk through your basic SBOM360 Hub actions.

### &#x20;Upload

Every user may need to upload an SBOM at some point. To do this:

* Select Upload in SBOM360 Hub
* Drag and drop or browse your files to add your project docset
  * NOTE: an SBOM docset zip file is a PDF containing at least the Self-Attestation document (SAL)
* Select Upload
* Allow some time for the SBOM to fully upload

<br>

### Download & Delete

Download​/Delete Instructions

You can download SBOM projects to save different SBOM versions and add data to other projects. Delete published SBOMs to make sure that only up to date SBOMs are within your repository.

* Select the box to the left of your desired SBOM in the My SBOMs tab
* Go to the right of the screen and click the button with 3 vertical dots
* Press Download or Delete
  * You may still need to request access to this SBOM if you do not own it or if the owner has not shared it with you. Go to the SBOM Request instructions for more on this process.

<br>

### Assess & Export

#### Assess​

Assessing your completed SBOM and compiling the information into a report has never been easier! There are two ways to generate an assessment:

* Assess & Export
  * Select the box to the left of your desired SBOM.
  * Go to the right of the screen and click the button with 3 vertical dots.
  * Click Assess & Export
* Assess
  * Select the blue SBOM Name on the left to open the View window.
    * NOTE: You must request access to this SBOM if you do not own it or if the owner has not shared it with you. Go to the SBOM Request instructions for more on this process.
    * Click the Assess SBOM button in the top-right corner.

#### Export​

Upon developing an acceptable assessment, you can immediately save it as a PDF to your computer.

NOTE

To export an SBOM with the Assess SBOM button that you do not have full access to, you must request access from the SBOM owner. Go to the SBOM Request instructions for more on this process.

<br>

<br>


# Request and Share SBOMS

For SBOMs that you did not create nor was invited to review, you will need to send a request for full detail access. Similarly, if you get an access request or need to provide an individual with SBOM access, review the Share document.

### Requesting

While you will be able to see all the published SBOMs and their overviews in the SBOM tab, you will not have authorization to open the SBOM *View Details feature*. You must first send a request to your fellow collaborator to gain total access to their project or projects. To do this:

* Select the box to the left of your desired SBOM in the SBOMs tab
* Go to the right of the screen and click the Request button
* Choose the SBOM’s supplier
  * You can select either Single Request or Request All
* For Single Request:
  * Ensure the correct SBOM Name and Version has been entered
  * Enter the SKU code (this is optional)
  * Click Next
  * Select the box to the left of your desired SBOM
  * Press Request
  * Check your email for a confirmation or rejection email.
* For Request All:
  * Ensure that the correct supplier title has been entered
  * Press Next
  * Select the box to the left
  * Click Request
  * Check your email for a confirmation or rejection email
* Choose the vendor and click Request

Contact your admin if neither a confirmation nor rejection email has been received.

### Sharing

SBOM360 User​

No matter what your user role is, once you create and publish an SBOM, you can share it with anyone within your organization. To create and publish an SBOM, go to Lineaje’s Create an SBOM document and choose either Configure Integration or Custom Configuration.

Sharing SBOM requires only a few steps:

* Select the box to the left of your desired SBOM in the My SBOMs tab
* Go to the right of the screen and click the Share button
* Select the parameters you need to share with your vendor
* Press Next
* Choose the vendor you would like to share your SBOM with
  * You may need to add a vendor with the New Vendor button on the right side of the screen. See the below instructions:
  * The user should receive an email informing them that an SBOM has been shared with them. They can either accept the invitation or ignore the email to reject it

### Note​

You may need to create/integrate a user in your organization. Check out our guides *Manage Users* and *Manage Vendors*.

<br>

<br>


# Settings

Read about user configurations and the options available to you.

### Configure Users

SBOM360 users can be created independently, or they can be proposed by current users.

### Manage Users

SBOM360 user accounts provides the basic set of SBOM permissions within your organization. In this page, you can edit the user roles which directly impact those permissions. To further define SBOM360 user positions, add them as vendors.

### Add Users

If you need/want the contribution from someone who is not yet an SBOM360 user, you will need to invite them. To add a user, go to Settings and press Manage Users. Either way, you will follow the same processes:

* Go to Settings and press Manage Users
* Navigate to the right corner of the list
* Press New User
  * You can either add an individual user or multiple at once
* For the individual options:
  * Add the new user’s information
  * Press Save
  * Wait for the user to accept the invitation and create an account
  * Admins must confirm the new user and assign them a role to proceed
  * The new user will then need to confirm their email address and sign in to SBOM360
* For the multiple option:
  * Click the Add Multiple button
  * Download the Bulk CSV template below the Upload File box
  * Fill out the template with all the users you wish to add
  * Drag and drop or browse your computer files and upload the completed template
  * Wait for the users to accept the invitation and create an account
  * Admins must confirm the new users and assign them all a role to proceed
  * The new users will then need to confirm their email address and sign in to SBOM360

### Current Account Holder

In Settings, within the Manage Users option, you will be able to manipulate the information your organization has connected to their users. This includes a unique search bar to locate specific users, the ability to edit user roles, and an option to delete users.

Moreover, the most notable feature is the New User process:

* Go to the Settings page listed in the nav bar
* Select Manage Users
* Press the New User button
* Enter the user information as described in the Add Users section above

### Configure Vendors

Keep your stakeholders involved in your SBOM creation process by inviting them to join your SBOM360 organization!

### Manage Vendors

In SBOM360, the vendors are essentially groups of positions within the SBOM creation procedure. It helps organize information according to what role they play in your SBOM production and the kinds of permissions they will be given for your organization.

In Settings, within the Manage \[Vendor Type] pages, you will be able to manipulate the information you have connected to your company's vendors. This includes a unique search bar to locate specific users, in-depth vendor information pages, and an option to delete the vendors. Moreover, the most notable feature is the New \[Vendor Type] process.

### Current Account Holder

It is easy to invite an active SBOM360 vendor to join your organization's network:

* Go to the Settings page listed in the navigation bar
  * You can also go to the vendor type tab in SBOM360 Hub and select the New \[Vendor Type] button (e.g., New Producer button).
* Select the vendor type (Producer, Consumer, Distributor, and Reseller) you would like to manage
* Press the New \[Vendor Type] button
* Enter the user information as normal on the page
  * Jump to the Brand New User section below to read more about the new vendor addition information requirements.

### Brand New User

If you are trying to interact (e.g., attempting to share SBOMs) with someone who is not yet an SBOM360 user, you will need to add them to your organization. To add a user, you will follow this process:

* Navigate to the right corner of the list
* Press New \[Vendor Type]
  * You can either add an individual user or multiple at once
* For the individual options:
  * Add the new user’s information
  * Press Save
  * Wait for the user to accept the invitation and create an account
  * Admins must confirm the new user and assign them a role to proceed
  * The new user will then need to confirm their email address and sign in to SBOM360
* For the multiple option:
  * Click the Add Multiple button
  * Download the Bulk CSV template below the Upload File box
  * Fill out the template with all the users you wish to add
  * Drag and drop or browse your computer files and upload the completed template
  * Wait for the users to accept the invitation and create an account
  * Admins must confirm the new users and assign them all a role to proceed
  * The new users will then need to confirm their email address and sign in to SBOM360

<br>


# User Roles

While each user roles will use SBOM360/Hub features differently, they do all share a few basic responsibilities and details.

### User Roles

#### What Are Roles?

Roles describe the positions individuals hold for SBOMs in their organization. These roles determine the permissions you are granted within SBOM360 and SBOM360 Hub. Users can be given more than one role at a time and the Tenant Admin can edit user roles whenever necessary.

<br>

### Development, Security, & Operations

Users who are assigned the Development, Security, and Operations role are intertwined with both the software producer and consumer positions. Typically, they have goals around creating SBOMs, analyzing SBOM data, and remediating vulnerabilities to produce and distribute high-quality, secure software.

<br>

### Procurement Manager

The Procurement Manager role relates to consumer tasks. Maintaining a focus on company stakeholder and audience satisfaction is a priority. This role will use SBOM360 and SBOM360 Hub to optimize communication, workflow, and quality of the SBOM assets and results for their product's end-users.

<br>

### Sales

Sales members are aligned with your organization's consumer position. Since their first concern directly correlates with the finished product, they will likely spend most of their time in SBOM360 Hub managing published SBOMs.

<br>

### SBOM Approver

The SBOM Approvers are a part of the producer position. Therefore, they are given access to review the SBOMs assigned to them before it gets published to SBOM360 Hub. Approvers are essentially your organization's SBOM quality assurance.

<br>

### Tenant Admin

Visit our document Tenant Admin for more information on this role.

<br>

### Notifications

Get an explanation on the SBOM360 notification system.

Your Notifications

In the top-right corner of both SBOM360 and SBOM360 Hub, there is a bell icon. This is your notification menu. Whenever communication for your organization's SBOMs is necessary, you will receive a red alert in your notifications. These alerts include:

* SBOM Updates
* SBOM Requests
* SBOM Assessments
* Invalid Vendors

If you are a tenant admin, you may also get alerts for:

* SBOM Approvals
* User Acceptance
* Vendor Additions
* New User Onboarded

<br>

<br>


# SCA360: Secure Deployment for Restricted Environments

Lineaje SCA360 is a cloud-native, contextual risk assessment tool that unifies all application security (AppSec) findings with Lineaje’s software crawling and analysis engines. It scans source code, artifact repositories, and containers to identify vulnerabilities and risks across the software supply chain.

With pre-deployed scanners, SCA360 detects security issues at every stage of software development, providing deeper context than ever before. This enables centralized risk prioritization and remediation planning to reduce the attack surface.

## Key Features

SCA360 has the following key features:

* **Safe Scanning**: Scans private source code, artifact repositories, and container images within an organization’s security boundaries, ensuring critical and proprietary IP remains fully protected and never leaves the environment.
* **Deep Dependency and Reachability Scanning**: Leverages Lineaje’s unique ability to enumerate all dependencies, including static dependencies, to derive mandatory and optional dependency chains and assess their inherent risks.
* **Malware Scanning**: Detects embedded malicious and tampered packages, highlighting those of dubious origin.
* **Additional Scanners**: Includes end-to-end software attestation, code quality checks, security posture analysis, provenance verification, geo-provenance, and more for comprehensive risk assessment and centralized prioritization.

## Before You Begin

Downloading SCA360 provides an even more accessible route for you to upload content to SBOM360.

* [System Configuration](/sca360-secure-deployment-for-restricted-environments/system-configuration)
* [SCA360 Installation](/sca360-secure-deployment-for-restricted-environments/sca360-installation)
* [SCA360 Usage](/sca360-secure-deployment-for-restricted-environments/sca360-usage)
* [Support Matrix](/sca360-secure-deployment-for-restricted-environments/support-matrix)


# System Configuration

System must meet specific hardware and software specification to install and use SCA360. Review the requirements before installing SCA360.

### Hardware

#### SBOM generation

<table><thead><tr><th width="198">Component</th><th>Requirements</th></tr></thead><tbody><tr><td>Processors</td><td><p>Intel x86_64 architecture-based processor</p><ul><li>Minimum: 2 vCPU</li><li>Recommended: 4 vCPU</li></ul></td></tr><tr><td>Memory</td><td><p>Minimum: 2 GB RAM</p><p>Recommended: 4 GB RAM </p></td></tr><tr><td>Disk space</td><td><p>Output Directory – Minimum 100 GB </p><p>“/tmp” Directory – Minimum 40 GB </p><p>“/home” Directory – Minimum 1 GB</p></td></tr></tbody></table>

#### SBOM and CBOM generation

<table><thead><tr><th width="198">Component</th><th>Requirements</th></tr></thead><tbody><tr><td>Processors</td><td><p>Intel x86_64 architecture-based processor</p><ul><li>Minimum: 3 vCPU</li><li>Recommended: 4 vCPU</li></ul></td></tr><tr><td>Memory</td><td><p>Minimum: 8 GB RAM</p><p>Recommended: 8 GB RAM </p></td></tr><tr><td>Disk space</td><td><p>Output Directory – Minimum 250 GB </p><p>“/tmp” Directory – Minimum 100 GB </p><p>“/home” Directory – Minimum 1 GB</p></td></tr></tbody></table>

### Operating System

Ubuntu 22.04 LTS

Red Hat Enterprise Linux 8

Note: CLI cannot be run on 32bit platform

### Additional Software requirement

CLI requires the following software to be available on the system

* Git Client

For language decomposition, please refer [Toolset Configuration](/sca360-secure-deployment-for-restricted-environments/toolset-configuration).

Following software can also be installed to help in troubleshooting&#x20;

* unzip&#x20;
* &#x20;strace
* screen/tmux
* gdb&#x20;
* wget / curl
* vim
* tcpdump
* jq

### Security and Firewall requirements

<table><thead><tr><th width="154">Port</th><th>Usage</th></tr></thead><tbody><tr><td>TCP/443</td><td><p>SCA360 will use this port to connect to the SBOM360 backend </p><p>SCA360 will use this port to fetch data from public repositories</p></td></tr></tbody></table>

### Privileges configuration

<table><thead><tr><th width="154">Privilege type</th><th>Usage</th></tr></thead><tbody><tr><td>Regular User</td><td>SCA360 can be executed by a regular user. There is no need to provide root or sudo privileges to the user that will run SCA360. This regular user should have a proper home directory</td></tr><tr><td>Network access</td><td><p>SCA360 requires access to connect to external networks on the ports mentioned in the “Firewall requirements” table </p><p>Depending on the configuration, SCA360 will also require access to connect to internal source and package repositories</p></td></tr><tr><td>Execution access</td><td><p>SCA360 will execute the following, </p><p>• Third party tools that SCA360 ships internally inside the “third_party” folder • “git” client to clone source code </p></td></tr></tbody></table>

### Domains to which access is required

This access is required to be configured only if the Firewall does not allow outgoing HTTPS connection by default.

<table><thead><tr><th width="336.727294921875">Services accessed</th><th></th></tr></thead><tbody><tr><td>Lineaje Backend Services</td><td><p>https://*.v2.prod.veedna.com <strong>OR</strong></p><p>https://data-service-v2-apigw.v2.prod.veedna.com<br>https://notification-service.v2.prod.veedna.com</p><p>https://lineaje-gpt-service.v2.prod.veedna.com</p><p>https://lineaje-identity-service.v2.prod.veedna.com</p><p>https://scim-service.v2.prod.veedna.com<br>https://lineaje-idp-service.v2.prod.veedna.com</p></td></tr><tr><td>Upload SBOM metadata</td><td>https://us-east-1-commercialprod-veedna-opa.s3.amazonaws.com/*</td></tr><tr><td>UI</td><td>https://app.veedna.com</td></tr><tr><td>Download reports</td><td>https://us-east-1-commercialprod-veedna-sbomreport-bucket.s3.amazonaws.com/*<br><br>https://us-east-1-commercialprod-veedna-datapipeline.s3.amazonaws.com/*</td></tr><tr><td>Gold Open Source Artifactory</td><td>https://enforce.fortknox.v2.prod.veedna.com<br>https://observe.fortknox.v2.prod.veedna.com</td></tr><tr><td>Local Vulnerability Lookup</td><td><p>https://*.anchore.io <strong>OR</strong></p><p>https://toolbox-data.anchore.io/<br>https://grype.anchore.io</p></td></tr><tr><td>Malware Lookup</td><td>https://data.reversinglabs.com</td></tr><tr><td>Maven and Gradle Package Repository</td><td><p>https://repo.maven.apache.org</p><p>https://repo1.maven.org</p><p>https://repo.spring.io</p><p>https://oss.sonatype.org</p><p>https://maven.google.com<br>https://dl.google.com</p></td></tr><tr><td>NPM and JavaScript Package Repository</td><td>https://registry.npmjs.org<a href="https://registry.npmjs.org"></a></td></tr><tr><td>Python Package Repository</td><td>https://pypi.org</td></tr><tr><td>Rust Package Repository</td><td>https://crates.io</td></tr><tr><td>Ruby Package Repository</td><td>https://rubygems.org</td></tr><tr><td>Dotnet Package Repository</td><td>https://api.nuget.org</td></tr><tr><td>Go Package Repository</td><td>https://sum.golang.org<br>https://proxy.golang.org<br>https://golang.org<br>https://google.golang.org<br>https://pkg.go.dev</td></tr><tr><td>Packagist Repository</td><td>https://packagist.org</td></tr><tr><td>Source Repository</td><td><p>https://github.com </p><p>https://bitbucket.org </p><p>https://gitlab.com</p></td></tr><tr><td>Ubuntu Container</td><td><p>https://*.ubuntu.com <strong>OR</strong> https://archive.ubuntu.com</p><p>https://security.ubuntu.com</p><p>https://old-releases.ubuntu.com</p></td></tr><tr><td>Debian Container</td><td>https://*.debian.org <strong>OR</strong><br>https://ftp.de.debian.org</td></tr><tr><td>Red Hat Container</td><td><p>https://*.redhat.com <strong>OR</strong><br>https://sso.redhat.com</p><p>https://api.access.redhat.com</p><p>https://cdn-ubi.redhat.com</p></td></tr><tr><td>Alpine Container</td><td><p>https://*.alpinelinux.org <strong>OR</strong><br>https://build.alpinelinux.org</p><p>https://dl-cdn.alpinelinux.org</p></td></tr><tr><td>Amazon Linux Container</td><td>https://*.amazonlinux.com <strong>OR</strong><br>https://cdn.amazonlinux.com</td></tr></tbody></table>


# Toolset Configuration

Depending on your source code, different toolsets might be required to be installed on the VM where SCA360 is installed. These toolsets basically mimic your (customer's) build environment.

SCA360 carries a set of toolsets to help simplify the process. The toolset configuration is maintained by SCA360 in JSON files. Modify them only if necessary.

```
# Go inside the directory where CLI is extracted 
$ cd veecli 
# Use jq to see the Toolset JSON content files 
$ cat third_party/runtimes-config.json | jq . | less 
$ cat third_party/tools-config.json | jq . | less 
```

If your source code requires any toolset that is not carried by Lineaje SCA360, follow the below steps to install the appropriate version of the toolset that your source code needs.

### Python Toolset

If your source code requires python, please setup and configure appropriate version of python.

#### Native python Toolset

SBOM generation can also be done using the default Python available in the system.

```
# Verify python is available in the environment. 
$ which python 
# Verify the minimum version of pipdeptree available in the environment is 2.3.3 and above 
$ pip show pipdeptree 
# Install “pipdeptree” using the following command, if not installed 
$ sudo pip install pipdeptree==2.3.3 
# Verify that python can be used to create virtual environments 
$ python -m venv /tmp/python-venv 
```

#### Setup python for Ubuntu (22.04)

Check what version of python your code requires and install the correct version. Steps to install Python 3.10 for ubuntu 22.04 is shown below for illustration. Python toolsets of different version can be installed in the same way.

```
# Go inside the directory where CLI is extracted 
$ cd veecli 
 
# Update APT Package Index Cache, sudo is required for this 
$ sudo apt-get update 
# Install the following packages from the default APT repository, sudo is required for this 
$ sudo apt-get install apt-utils pkg-config git tar wget build-essential unzip jq -y 
$ sudo apt-get install libssl-dev libpq-dev libffi-dev libsqlite3-dev -y  
$ sudo apt-get install python3-pip python3-venv -y 
 
# NOTE: Ensure that the following steps are executed inside the extracted veecli folder 
# Download and locally compile Python 3.10 
$ wget -q https://www.python.org/ftp/python/3.10.8/Python-3.10.8.tgz 
$ tar -xzf Python-3.10.8.tgz 
$ mkdir -p third_party/linux/python310 
$ cd Python-3.10.8 
$ ./configure -prefix=$(pwd)/../third_party/linux/python310 > /dev/null 2>&1 
$ make install > /dev/null 2>&1 
$ cd - 
 
# Verify that Python 3.10 binary was correctly compiled by checking for its presence 
$ ls -al third_party/linux/python310/bin/python3.10 
 
# Install tools required for dependency generation 
$ sudo pip install pipdeptree==2.3.3 
 
# Cleanup files 
$ rm -rf Python-3.10.8
$ rm -rf Python-3.9.15
```

###


# SCA360 Installation

### Download CLI

<figure><img src="/files/oI0KlDhnmaGNkiwam6L6" alt=""><figcaption></figcaption></figure>

1. Log in to the SBOM360 portal at <https://app.veedna.com>
2. From the left-hand navigation, choose **Integrations**.
3. Click **Download CLI** > **Download SBOMDetect CLI**
4. Extract the CLI with the below steps

```
# Run these commands as a regular user
# Extract the veecli.tar.gz
ubuntu@ip-a.b.c.d:~$ tar -xzf veecli.tar.gz
# This will create a directory called veecli
ubuntu@ip-a.b.c.d:~$ cd veecli
# Run pre.sh to set the permissions of the CLI and associated files
ubuntu@ip-a.b.c.d:~$ bash pre.sh
```

6. Go back to SBOM360 portal and click on "Verify Device" (Step-2)

<figure><img src="/files/vwblQGscLU95tENsg0Oj" alt=""><figcaption></figcaption></figure>

7. Click on "Verify Link" and a device confirmation code will appear

<figure><img src="/files/a8W9Wtw0XgSISu0TkSpq" alt=""><figcaption></figcaption></figure>

7. Click on “Confirm”
8. Provide the SBOM360 credentials when prompted the login page. If credentials are cached, then it may not prompt for the SBOM360 credentials again.

### Register CLI

1. Once the device registration is successful, a code will be displayed in SBOM360 portal. The device registration code is valid only for 5 min. If it expires, click on "Verify Device"->"Verify Link" again to get a new code.

<figure><img src="/files/Fjz97U7Icd1IlSgMKOdt" alt=""><figcaption></figcaption></figure>

2. Run the following commands from your ubuntu machine where CLI is extracted

```
# Run these commands as a regular user
# Go inside the directory where CLI is extracted
ubuntu@ip-172-31-26-185:~$ cd veecli
# Register the CLI with the SBOM360 backend using the device code obtained from portal
ubuntu@ip-172-31-26-185:~$ ./veecli register --devicecode npbP_fImda2Cj_Hzk9LgxJUn
2022-07-07T14:18:15.584+0300 info Starting to register veeCLI
2022-07-07T14:18:16.924+0300 info Successfully configured authentication
2022-07-07T14:18:16.924+0300 debug Signature in auth0 access token payload is 
unknown
2022-07-07T14:18:16.933+0300 info Authenticated for Tenant Name - ******, Tenant 
Id - vdna_************** and Device Code - npbP_fImda2Cj_Hzk9LgxJUn
2022-07-07T14:18:16.934+0300 info Successfully registered veeCLI
```

<br>

<br>




---

[Next Page](/llms-full.txt/1)

