The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Professional · Module 4: DevSecOps and supply chain · Lab

Build an SBOM and Prioritize Fixture Findings

45 min hands-on · Core

A local machine with a small fixture artifact and an SBOM generator; a provided fixture vulnerability feed. Findings are practice fixtures, labeled as such.

Local guide: run the steps below on your own machine in order, then check the validation list.

Objectives

  • Generate the SBOM at build from resolved dependencies
  • Triage findings by reachability and severity
  • Record what the list cannot prove
  1. Step 1

    Generate and read

    Build the fixture artifact and generate its SBOM from the resolved dependencies. Read it: components, versions, licenses quoted in the record.

  2. Step 2

    Triage like it matters

    Take the fixture findings feed and triage to the reachable and severe. Demote unreachable test-dependency findings with written reasons; promote the request-path findings with fix actions.

  3. Step 3

    State the limit

    Write what the SBOM practice proves (listing, triage skill) and what it does not (production verdicts). Fixture labels throughout.

How to confirm it worked

  • SBOM generated at build, readable in the record
  • Triage with reachability reasons quoted
  • Fix actions for the promoted findings
  • Fixture labeling and limit paragraph present