Quality, structure, and relationship signals for this SBOM.
A completeness score across this document's packages, weighted over five categories based on the NTIA "minimum elements" baseline. It is not a security or license-compliance measure; see the breakdown below for what to fix first.
Graph-visible relationship edges by type. Switch scope to isolate lifecycle layers.
Data fields from the 2026 SBOM baseline. Signature is advisory; SBOM Version is N/A for SPDX 3.
Categories with nothing to measure in this document (e.g. no files) are excluded and the remaining weights are renormalized.
Best-effort classification by license id — a heuristic, not legal advice.
Packages the most other packages depend on — the highest-impact links if compromised.
Elements this document references but doesn't define (SPDX ExternalMap imports).
How much of this document's known vulnerabilities have a resolved VEX status.