DevOps Professional · Module 4: DevSecOps and supply chain · Lab
Build an SBOM and Prioritize Fixture Findings
45 min hands-on · Core
A local machine with a small fixture artifact and an SBOM generator; a provided fixture vulnerability feed. Findings are practice fixtures, labeled as such.
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Generate the SBOM at build from resolved dependencies
- Triage findings by reachability and severity
- Record what the list cannot prove
Step 1
Generate and read
Build the fixture artifact and generate its SBOM from the resolved dependencies. Read it: components, versions, licenses quoted in the record.
Step 2
Triage like it matters
Take the fixture findings feed and triage to the reachable and severe. Demote unreachable test-dependency findings with written reasons; promote the request-path findings with fix actions.
Step 3
State the limit
Write what the SBOM practice proves (listing, triage skill) and what it does not (production verdicts). Fixture labels throughout.
How to confirm it worked
- SBOM generated at build, readable in the record
- Triage with reachability reasons quoted
- Fix actions for the promoted findings
- Fixture labeling and limit paragraph present