- The project needs at least one completed scan. See Your first scan.
- Triage the findings first. An SBOM records your current decisions, so a project you haven’t triaged produces an SBOM with low review coverage. See Triaging findings.
- You need the Operator or Admin role to generate a snapshot. Viewers can download existing snapshots but can’t create them.
What an SBOM is, in Earnie

Snapshots are immutable. Earnie never edits a snapshot. If the inventory changes, you
generate a new one. A document you sent to a customer last quarter still says exactly what it
said when you sent it.
Generating a snapshot
You can start from either of two places:- SBOMs in the sidebar → Generate snapshot
- Review in the sidebar → Export SBOM, which generates a snapshot of the scan you’re reviewing
-
Choose a scope. A scope preset picks which sections the snapshot holds. The panel offers only the presets your organisation’s scanning covers:
SPDX is available only for the SBOM scope. Earnie names downloaded files after the scope, for example
…-cbom, or…-sbom-aibomfor a custom mix. -
Choose one or more documents. You must choose at least one, and you can choose both:
You can render the other format later from the same snapshot.
-
Choose what to embed in CycloneDX (optional). These options are available only when you select CycloneDX. SPDX doesn’t support them. Both are off by default.
- Known vulnerabilities embeds known vulnerability data. Each advisory names only the affected versions in the snapshot. When several sources report the same CVE, the document keeps the highest severity and scores, and names every source that reported it.
- Cryptographic assets adds detected algorithms as CycloneDX cryptographic assets, which makes the document a CBOM (cryptography bill of materials). It also produces the export-control evidence report. This option appears only when cryptography scanning is enabled for your organisation.
- Select Generate snapshot.
422 scan_evidence_unavailable. Earnie stores nothing. Generate SBOMs on All projects reports such a project the same way and generates SBOMs for the other projects.
Licences and tool information in the document
- Concluded and detected licences. A component you confirmed carries the licence you concluded and, next to it, the licence the scan detected. CycloneDX records them as separate licence entries marked
concludedanddeclared. SPDX records them aslicenseConcludedandlicenseDeclared. The notice file names only the concluded licence. - Generating tool. Every CycloneDX and SPDX document names Earnie and the build that generated it as its tool, for example
earnieand its version. A document filed with an auditor says which release produced it. If you render a format later from the same snapshot, that document names the build that rendered it, which can be a newer release.
What the snapshot records
Earnie stamps each snapshot with:- Reviewed, the review coverage when the snapshot was generated
- Components, the number of components
- Generated by, the person who generated it
Cryptographic asset details
When Cryptographic assets is on, the CycloneDX document has extra detail for each asset:- Export-control metadata. Each cryptographic-asset component has
scanoss:exportControl:*properties. They record the rolled-up signal state, the asset’s purpose, and the control regime and regime version Earnie evaluated the signals against. - Sizes. Key, nonce, salt, and IV assets have their size under
relatedCryptoMaterialProperties.size, when Earnie resolved it. - Curves. Elliptic-curve algorithms have their curve under
algorithmProperties, when Earnie resolved it.
When a snapshot is out of date
If triage has changed since a snapshot was generated, its row shows a Stale badge. Hover it to see “Triage has changed since this snapshot was generated.” Generate a new snapshot before you send it out.How decisions carry into a snapshot
A new SBOM or CBOM uses each finding’s current decision, never a withdrawn or superseded one.- Reopening a finding restores its unreviewed evidence for the next snapshot.
- Excluding or replacing one occurrence of a component doesn’t remove another occurrence of the same component that’s still present.
- If the remaining occurrences disagree on known component metadata, generation stops with a
resolution_conflicterror. Reconcile those findings’ decisions in Review, then generate again. Existing snapshots and downloads don’t change.
CRA SBOM annex
The CRA SBOM annex is a CycloneDX 1.7 export for the EU Cyber Resilience Act (CRA). It includes the detected cryptographic assets as components. It goes with the product SBOM. It is not a CRA conformity assessment.Not the same CRA reference as a policy. This annex isn’t tied to a specific CRA clause. The
CRA — Annex I(2)(e) and CRA — Annex I Part II(1) regulatory template
sets are policies, not
an SBOM export. All three carry a “CRA” label, but they’re unrelated features.
Earnie doesn’t verify FIPS 140-3 module validation.
The snapshot list
Each row on the SBOM snapshots page shows when the snapshot was generated, the scan it came from, its documents, and the stamp described above. The Documents column shows a badge for each document the snapshot has:
From each row’s menu you can download a document, render a format the snapshot doesn’t have yet, copy the snapshot ID, regenerate from the same scan, or delete the snapshot.
The export-control evidence report
Some countries control the export of software that uses cryptography. The export-control evidence report collects the evidence you need to classify your own product under those rules. When a snapshot was generated with Cryptographic assets on, its row menu offers Download Export-control evidence report. The report is a self-contained HTML file, frozen with that snapshot. It records:- the detected cryptographic assets
- their export-control signals
- the detection surface it cites, meaning what was scanned
- the identity of the ruleset Earnie used
The report states that all detected cryptography maps to published standards only when its
frozen evidence shows that for the named detection surface. Otherwise it marks the statement as
not established. Signature-based detection can’t prove that no non-standard cryptography is
present. To cover a later scan, generate a new snapshot with Cryptographic assets on.
Notice files (attribution documents)
An SBOM and a notice file are different documents, and one can’t replace the other:- An SBOM lists what’s present and names each component’s licence.
- A notice file, also called an attribution document, contains the text you’re obliged to distribute. An OSPO (Open Source Program Office) ships it with a release.
- its licences
- the full text of its
LICENSEandNOTICEfiles - its copyright holders
- its obligations
Rendering a notice file
You don’t create a notice file in the Generate snapshot panel. Earnie renders it from a snapshot that already exists:- On the SBOM snapshots page, open the snapshot’s row menu.
- Choose Render Notice file.
Frozen on first render. The first time you render a snapshot’s notice file, Earnie fixes
its content. Later downloads return exactly the same file, even if the upstream licence text
changes. Hover the NOTICE badge to see when Earnie fetched the licence text, and compare that
date with what you’re about to ship.
Notice files elsewhere in Earnie
The same document is available in two other places:- On a project’s Dashboard, the Download menu offers it as Notice file. Earnie renders it from a snapshot, so a snapshot has to exist first. If there’s none, the Dashboard says “No SBOM snapshot exists for the current scan” instead of offering the notice file.
- On All projects, the Generate notice files action doesn’t need an existing snapshot. For a project with no current snapshot, it generates one and then renders the notice file from it, in one step.