SBOM Policies
SBOM policies control the quality, safety, and compliance of third party libraries. The policies validate dependency and artifact metadata including completeness, accuracy and licensing compliance across the supply chain.
The article describes the policies in this category, configuration options, and the impact of policy violations. For an overview of policies and policy management, see the Policies article.

SBOM policy categories
License
Unapproved license detected by 3rd party security app
Detects components identified by an integrated third-party security tool as using licenses that are not approved by your organization.
License
Unapproved license used by direct dependency in code
Checks direct dependencies in the codebase for licenses that are not approved by your organization.
License
Unapproved license used by indirect dependency in code
Checks indirect (transitive) dependencies for licenses that are not approved by your organization.
License
Unapproved license used in forked open source
Checks forked open-source projects for licenses that are not approved by your organization.
Maintenance
Deprecated direct dependency in code
Identifies direct dependencies in the codebase that are marked as deprecated by their maintainers.
Maintenance
Deprecated indirect dependency in code
Identifies indirect dependencies that are marked as deprecated by their maintainers.
Maintenance
Outdated direct dependency in code
Detects direct dependencies that do not use the latest available versions.
Maintenance
Outdated indirect dependency in code
Detects indirect dependencies that do not use the latest available versions.
Maintenance
Unpopular direct dependency in code
Identifies direct dependencies with low adoption or usage signals in the ecosystem.
Maintenance
Unpopular indirect dependency in code
Identifies indirect dependencies with low adoption or usage signals in the ecosystem.
Maintenance
Unused direct dependency in code
Detects direct dependencies that are declared but not referenced in the codebase.
Malware
Dependency confusion: organization scope in code
Detects dependency confusion risks where public packages may override organization-scoped packages.
Malware
Dependency confusion: private package in code
Detects dependency confusion risks involving private packages that may be shadowed by public packages.
Malware
Malicious dependency in code
Identifies dependencies that are known or suspected to contain malicious code.
Malware
Typosquatting dependency in code
Detects dependencies with names that closely resemble popular packages and may indicate typosquatting.
Malware
Untrusted source for dependency in code
Identifies dependencies that are downloaded from sources not approved or trusted by your organization.
License policies
For license policies, see the article License policies.
Maintenance policies
Open each policy to view the business impact and optional settings.
Malware policies
Open each policy to view the business impact and optional settings.
Open the Active Issues page.
Use the Category filter and select the policy category to view related active issues.
Use the Policy filter to narrow the list to a specific policy.
Apply the Category and Policy filters separately or together, depending on how specific you want the results to be.
Use the search box to refine results, such as filtering by file name, keyword, or rule identifier.
You can also use the Issues filter on the SBOM page.
When you change a policy’s severity, ON/OFF toggle or any other setting, you must save the current profile or create a new one.
To save the current profile, click SAVE in the page header.
To create a new profile, click SAVE AS in the page header. For instructions, see the section Create or edit policy profiles in the Policies article.
Last updated












