Getting Started
Getting Started
Set up your Tenant
Cloud
After purchasing a Lifecycle SBOM Manager license, Sonatype will initialize an SBOM Manager instance for you, based on the specifications discussed during the sales process. This initialization period depends on the time to allocate resources in your region. When the server is ready, you will receive an email with a URL to the browser UI. This URL is unique to your organization and should be treated as sensitive information.
You can access your Cloud Solutions from the Solutions page on my.sonatype.com.
Self-Hosted
Initialize your tenant and designate your support contacts and administrators on my.sonatype.com.
Refer to the IQ server system requirements and installation instructions for self-hosted deployments.
Note
SBOM Manager requires using the PostgreSQL database for self-hosted deployments.
Organizations are simple ways to group applications to align with your business units and stakeholders. Use them to manage access control to your applications and SBOMs. We recommend aligning them to your organization's structure and grouping third-party SBOMs by their source vendor. You may also wish to group sets of microservices into a single nested organization for reporting.
Applications are the software in SBOMs and are comprised of open-source components and your custom source code. They may be individual scripts, microservices, or monolithic websites. How you define them is up to you.
You may add applications manually or automatically from your build pipeline.
SBOMs align to specific versions of your applications. We recommend creating and importing an SBOM when your application is built and tracking dependency risk as long as your stakeholders use the version.
While the contents of a specific SBOM do not change, the risk associated with the open-source components may as new vulnerabilities are discovered. We use the VEX workflow to track and manage which issues that have been reviewed and remediated. Use Continuous Monitoring to automatically check for discovered risks and apply feedback to your efforts in managing those risks.
Share SBOMs with your stakeholders
After updating your VEX audit, automatically share your SBOMs with your stakeholders, providing them the peace of mind that you are fully compliant with any obligations.