Skip to main content

What is SBOM Workbench?

SBOM Workbench is a graphical user interface (GUI) desktop application designed to scan and audit source code using the SCANOSS API. It provides an intuitive way to identify open source components in your projects, analyse license compliance, detect vulnerabilities, cryptography and generate comprehensive Software Bills of Materials (SBOMs).

TL;DR

1. Install SBOM Workbench
  • Download the installer for your platform and run it
2. Configure Your API Access
  • File → Settings → add your Knowledgebase API details → Save
3. Scan Your Project
  • Open SBOM Workbench → New Project → select directory → configure settings → Continue
4. Review Detected Results (Reports → Detected)
  • Check metrics (matches, dependencies, vulnerabilities)
  • Review components and match percentages
  • Note Critical/High vulnerabilities, and review any cryptographic algorithms detected
5. Audit Components (Detected Components)
  • Review component cards → review files
  • Identify correct matches or Mark as Original
  • Add notes and process dependencies (Accept/Dismiss)
6. Verify Your Work (Reports → Identified)
  • Confirm metrics and notes
  • Verify identified components and decisions
7. Export Your SBOM (Identified → Export)
  • SPDX Lite – Legal compliance
  • CycloneDX (with vulnerabilities) – Security teams
  • CSV SBOM – Analysis/tracking
  • HTML Summary – Reports
  • scanoss.json – CI/CD automation

Installation

  1. Download the installer
  2. Select the appropriate installer for your platform:
    • macOS: .dmg file
    • Windows: .exe installer
    • Linux: .AppImage or .deb package
  3. Run the installer

Initial Configuration

  1. Open SBOM Workbench
sbom-wb-home
  1. Go to File → Settings
file-settings
  1. Click the ”+” button after Knowledgebase API
api-settings
  1. Enter your API details
    • Free tier: leave the default URL unchanged
    • Enterprise: replace the URL with https://api.scanoss.com
  2. Click Add → Save

How the API URL and Key Work Together

The API URL and the API key have distinct responsibilities. The API URL determines where SBOM Workbench sends its API requests, while the API key is used only to authenticate those requests against the configured endpoint. The API key does not influence or change the destination of any request. If a custom on-premise URL is configured, such as https://your-server:5443, all requests are instead sent exclusively to that on-premise deployment. If an on-premise deployment does not provide a particular dataset, the corresponding section in SBOM Workbench will remain empty, even though the same scan against SCANOSS service may return results.
If your organisation has an on-premise SCANOSS deployment, you must configure SBOM Workbench to use the URL of that on-premise deployment rather than the SCANOSS Enterprise API URL.

Workspaces

Local Workspaces

By default, SBOM Workbench stores your projects in a local workspace on your machine. This is where your scan results, project configurations and identification decisions are saved.

Shared Workspaces

SBOM Workbench supports shared workspaces, enabling teams to collaborate on projects from a common network location with centralised scan results and project configurations. Team members can work together with full read and write access, making identifications, adding notes and sharing decisions across the team. shared-workspace

Setting Up Shared Workspaces

To set this up, create a shared folder using Samba on your system, configuring read/write permissions for team members. To access the shared workspace, mount the network share using your OS’s native file-sharing tools. Then, in SBOM Workbench, go to My Workspace → Add new workspace, browse to the shared folder, select the workspace directory, and click Add. The shared workspace will appear in your workspace list, letting you switch to it and access any projects stored there. new-workspace

Multi-User Considerations and Access Control

Single-User Application Architecture

SBOM Workbench is a client-side desktop application. It is not designed for multiple users to access the same running instance simultaneously. Each user runs their own local installation of SBOM Workbench on their own machine. When using a shared workspace (e.g. over Samba), the recommended model is one user working on a given project at a time. Multiple users can share the same workspace and work on different projects concurrently, but two users should not open and modify the same project simultaneously, as this may lead to conflicts or data corruption.

Project-Level Access Control

SBOM Workbench does not include built-in user authentication or project-level permission controls. Access management must be handled at the file system level. If you need to restrict which users can access specific projects, use your network file system’s permission settings. For example, on a Samba server you can configure directory-level ACLs so that a given user only has access to the project folders assigned to them:
  • User A is granted read/write access to workspace/project-a/ only
  • User B is granted read/write access to workspace/project-b/ only
  • Neither user can browse or open the other’s project directory
This approach relies entirely on OS or Samba-level permissions and is independent of SBOM Workbench itself. Refer to your Samba or network file system documentation for instructions on configuring per-directory ACLs.
SBOM Workbench has no built-in login system, controlling access to sensitive project data is the responsibility of the administrator configuring the underlying file system or network share.