CERTISYNVERIFICATION INFRASTRUCTURE
Coverage checkWhat a scan read, and what it did not
Runs in your browser

Does this BOM account for what it read?

Drop in a CycloneDX BOM. The check reads the coverage statement the scanner carries and rules on it against the Coverage Attestation Profile, rule by rule. Nothing leaves this page.

CycloneDX JSON

What this check reads

It reads the statement a scanner makes about its own run. A count carried by file extension is a remainder, and rule R1 refuses a remainder because no one can check which files it holds. Reading a tree to name every file needs the files, which stay on your machine: run cbom-check.mjs <bom.json> --tree <dir> beside the repository.

A BOM that states no coverage in a shape this check recognises is reported as exactly that. The recognised shapes are listed in the result.