SBOM formats
CycloneDX 1.6 · SPDX 3.0.1
Reachability, Signed. Evidence, Replayable. Sovereignty, Built-In.
Stella Ops is a next-generation container vulnerability scanner that seals every reachability graph with in-toto + DSSE and replays scans bit-for-bit from frozen feeds.
Engineers trace impact instantly, auditors replay historical findings, and compliance teams meet regional crypto mandates—all while staying fully open and AGPL-licensed.

Bill-of-materials generation, vulnerability exchange, and signed attestations all use current, interoperable formats. Advisory mirrors pull from 30+ sources—national CERTs, distro trackers, vendor feeds, and global databases—as individual signed snapshots so your policy decides which sources to trust. See the full comparison.
CycloneDX 1.6 · SPDX 3.0.1
OpenVEX · Versioned lattice engine
in-toto DSSE · Sigstore Rekor
Signed graphs · Edge-level DSSE