Statistics

Quality, structure, and relationship signals for this SBOM.

/ 100

SBOM Quality Score

A completeness score across this document's packages, weighted over five categories based on the NTIA "minimum elements" baseline. It is not a security or license-compliance measure; see the breakdown below for what to fix first.

Relationship Repartition

Graph-visible relationship edges by type. Switch scope to isolate lifecycle layers.

No graph-visible relationships in this document.
Click a slice to open the graph focused on that relationship type and scope.

NTIA Minimum Elements

Cross-checked with spdx/ntia-conformance-checker in CI

CISA 2026 Minimum Elements

Data fields from the 2026 SBOM baseline. Signature is advisory; SBOM Version is N/A for SPDX 3.

Category Breakdown

Categories with nothing to measure in this document (e.g. no files) are excluded and the remaining weights are renormalized.

License Family Exposure

Best-effort classification by license id — a heuristic, not legal advice.

Supply-Chain Concentration

Packages the most other packages depend on — the highest-impact links if compromised.

External Reference Resolution

Elements this document references but doesn't define (SPDX ExternalMap imports).

Resolved
Unresolved

Vulnerability Triage

How much of this document's known vulnerabilities have a resolved VEX status.

Resolved
Still open
Unknown