A customer's procurement team asks for an SBOM.
Engineering exports a list of packages from one service, by hand, in a format nobody agreed on. The same week a dependency report lands with dozens of CVEs sorted by CVSS, and the team patches the top of the list — a 9.8 nobody has ever exploited — while a medium-rated library on CISA's known-exploited list ships in every build.
CVSS is not a to-do list
Severity describes the vulnerability, not how likely anyone is to use it against you. A queue sorted by CVSS alone spends the week on theoretical criticals while an actively exploited medium waits.
The mechanism, not the marketing
- 1
Onam parses manifests and lockfiles itself, without an external scanner: Python (requirements files, Pipfile.lock, pyproject.toml, setup.cfg), npm (package.json, package-lock.json, yarn.lock), Java (pom.xml, Gradle build files), Go (go.mod), Rust (Cargo.toml, Cargo.lock), Ruby (Gemfile.lock), .NET (project files, packages.config) and PHP (composer.lock). Where a lockfile exists, its pinned versions win over the manifest.
- 2
Each component is matched to known advisories — the OSV database first, the NVD as a fallback — using the same advisory store as Onam's vulnerability engine.
- 3
Every match is enriched with its EPSS score (the probability of exploitation in the next 30 days) and whether it is on CISA's Known Exploited Vulnerabilities list, both refreshed daily.
- 4
A composite 0–10 risk score combines CVSS, EPSS, KEV membership and whether a fixed version exists, and maps it to a priority: Immediate, High, Medium or Low. An actively exploited medium can outrank an unexploited critical — which is the point.
- 5
The component list is written out as a CycloneDX 1.5 SBOM with package URLs. You can also upload an existing CycloneDX (1.4 or 1.5) or SPDX 2.3 SBOM in JSON and get the same enrichment, compare two SBOMs, record VEX statements, and run license-policy and NTIA minimum-elements checks.
Specific outputs, measurable outcomes
How Dependencies & SBOM (SCA) fits together
Questions we get a lot
Ready to see Dependencies & SBOM (SCA) on your dependencies?
Send us a repository or an existing SBOM. We will show you the risk-ranked component list and the SBOM it produces.