bomber

Import bomber reports in JSON format. bomber reads an existing SBOM (CycloneDX, SPDX or Syft) and looks each component up against a vulnerability provider.

Generate a report with:

bomber scan --output json sbom.json > bomber.json

Severity Mapping

bomber normalises every provider onto its own scale, which uses MODERATE where most tools use medium:

bomber severityDefectDojo severity
CRITICALCritical
HIGHHigh
MODERATEMedium
LOWLow
UNSPECIFIEDInfo

Package coordinates are reported as a purl and split into the component name and version. Advisory identifiers are recorded in vuln_id_from_tool; those that are CVEs are additionally attached as vulnerability ids, while provider-specific ids such as GHSA references are not.

Sample Scan Data

Sample bomber scans can be found here.

Default Deduplication Hashcode Fields

By default, DefectDojo identifies duplicate Findings using these hashcode fields:

  • vuln_id_from_tool
  • component_name
  • component_version