A new CVE drops
01 CVE-2025-XXXXX hits the OSS feed at 09:14 UTC. CVSS 9.1, exploit in the wild. Your AppSec team has thirty minutes before the first all-hands ping.
Open the SBOM
02 Top-level nav → SBOM. Pick the org-wide snapshot or one per repo. Pre-rendered, queryable, current as of the last install through the proxy.
Search the CVE
03 Paste the CVE ID. The SBOM resolves the affected package + version ranges and lists every direct importer, with transitive dependents one click deep. Closure size and max depth on every row.
Export the incident snapshot
04 Click export. A CycloneDX 1.6 file with the affected component, its transitive blast radius, and a deterministic incident-tied hash. Drop it in the SOC 2 evidence folder, attach it to the customer notice, ship.