Skip to content
SB.00Software Bill of Materials

2,669 components, public, signed, audited.

Every FlyttGo module ships a CycloneDX 1.6 SBOM at release. Sigstore-signed, SLSA L3 build provenance attached, CVE-cross-referenced every six hours. Most platform vendors keep this internal — making it public is the procurement floor.

SB.SUMCross-module summary
  • Modules
    8
  • Components total
    2,669
  • Critical CVEs · open
    0
  • High CVEs · open
    0
SB.PRSupply-chain posture

Four floors procurement teams expect.

  • SB.PR.01

    CycloneDX 1.6 per release

    Every release of every module emits a CycloneDX 1.6 SBOM at build time. Spec-conformant, machine-readable, ingestible by Dependency-Track, GitHub Dependabot, OWASP Defectdojo and any compliant scanner.

  • SB.PR.02

    Sigstore-signed artefacts

    Container images, release archives and the SBOM itself are Cosign-signed. Tenants can require signature verification at admission via the platform-policy API; the signing key chain is published alongside the SBOM.

  • SB.PR.03

    SLSA Build Level 3 provenance

    Hosted-builder SLSA L3 — provenance attestation states which source revision, which builder, which build steps produced the artefact. Stops a compromised dev laptop from producing a published artefact.

  • SB.PR.04

    CVE cross-reference + auto-revoke

    SBOMs are cross-referenced against the OSV.dev and NVD vulnerability databases on every release and every 6 hours thereafter. New high or critical CVE on a published artefact triggers an automated revocation channel + customer notification.

SB.RGPer-module SBOM registry

Eight modules, current release per row.

  • SB.TRTransifyv1.14.7released 2026-04-30
    384 componentsNo high/critical CVEs
    Top dependencies
    next@14.2postgres@16.2redis@7.2opentelemetry@1.26
    Attestations
    SLSA L3SigstoreCycloneDX 1.6
  • SB.WKWorkvergev1.09.3released 2026-04-22
    312 componentsNo high/critical CVEs
    Top dependencies
    next@14.2postgres@16.2opentelemetry@1.26pg-boss@9.0
    Attestations
    SLSA L3SigstoreCycloneDX 1.6
  • SB.CVCivitasv1.18.0released 2026-04-14
    421 componentsNo high/critical CVEs
    Top dependencies
    next@14.2postgres@16.2redis@7.2opentelemetry@1.26
    Attestations
    SLSA L3SigstoreCycloneDX 1.6
  • SB.EDEduProv1.11.5released 2026-04-07
    298 componentsNo high/critical CVEs
    Top dependencies
    next@14.2postgres@16.2opentelemetry@1.26kafka@3.7
    Attestations
    SLSA L3SigstoreCycloneDX 1.6
  • SB.IDIdentrav1.22.1released 2026-03-18
    256 componentsNo high/critical CVEs
    Top dependencies
    next@14.2postgres@16.2jose@5.9opentelemetry@1.26
    Attestations
    SLSA L3SigstoreCycloneDX 1.6eIDAS-aligned
  • SB.PVPayverav1.19.4released 2026-04-30
    412 componentsNo high/critical CVEs
    Top dependencies
    next@14.2postgres@16.2redis@7.2iso20022-tools@2.4
    Attestations
    SLSA L3SigstoreCycloneDX 1.6PSD2-aligned
  • SB.LDLedgerav1.06.2released 2026-04-04
    219 componentsNo high/critical CVEs
    Top dependencies
    next@14.2postgres@16.2opentelemetry@1.26kafka@3.7
    Attestations
    SLSA L3SigstoreCycloneDX 1.6
  • SB.MPFlyttGo Marketplacev1.07.8released 2026-04-22
    367 componentsNo high/critical CVEs
    Top dependencies
    next@14.2postgres@16.2redis@7.2transify-sdk@1.14
    Attestations
    SLSA L3SigstoreCycloneDX 1.6

CVE counts refresh every six hours. Each download link returns the current CycloneDX 1.6 JSON with attached signatures and provenance manifest. Older releases archived under /sbom/{module}/{version}.