docs(sbom): document the Asset-page export and the version it produces - #15671
Merged
Conversation
The Exporting SBOMs and VEX page covered only the token-auth API endpoints. The Asset page's own Export panel — SBOM, VEX and SBOM with vulnerabilities (VDR) — was undocumented, so the three choices and what each one produces were discoverable only by using them. Adds a section describing the three export types and notes that each choice now names the format and specification version it produces. Also states that the Asset page and the API emit the same specification version, so a document from either path is interchangeable with the other.
blakeaowens
approved these changes
Aug 14, 2026
Maffooch
approved these changes
Aug 14, 2026
devGregA
approved these changes
Aug 14, 2026
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
[sc-14491]
Description
The Exporting SBOMs and VEX page documented only the token-auth API endpoints. The Asset page's own Export panel — SBOM, VEX, and SBOM with vulnerabilities (VDR) — had no documentation at all, so the three choices, and what document each one produces, were discoverable only by exporting one and reading the result.
This adds a section covering that panel:
Docs-only; no code changes in this repo.
Pairs with a DefectDojo Pro change on the same release line that adds the version to those labels and unifies the specification version across the two export paths.