Locations

Container Image Locations →

Container Image locations model the image a finding was found in, identified by registry, repository and digest, and the assets that run it

Exporting SBOMs and VEX →

Export an Asset's dependency inventory as CycloneDX or SPDX, and its finding statuses as a CycloneDX VEX document

Locations Overview →

What Locations are and why they replace Endpoints

Migrating From Endpoints →

What happens when you migrate existing Endpoint data to Locations

Source Code Locations →

Code locations model where a static-analysis finding lives in source, and record its movement history as code evolves

Working With SBOMs →

Manage software dependencies and SBOMs as Locations

Working With URLs →

Day-to-day use of URL Locations as the Endpoints replacement