SBOM and software inventory
For the selected release artifact, a software inventory records identified components, dependencies, and relevant relationships. A software bill of materials (SBOM) is a machine-readable inventory. Coverage depends on the agreed source or build data, so it is not a vulnerability report or proof that every component is known.