Analyze CyclonceDX/SPDX report file
In the SBOM area, CycloneDX is typically used for vulnerability tracking, whereas SPDX focuses more on software license information. The SBOM module can take these reports, then adding any missing components such as CVE details, license details, and library information. This process produces a fully enriched SBOM that combines both security and compliance insights for more accurate analysis and reporting.


Supported format: CyclonceDX JSON v1.5/1.6, SPDX JSON v2.3
