SSolarc Labs
Resources/Template/SBOM Risk Pack
Copyable workflow

SBOM licence disposition checklist

A reusable review checklist for component normalisation, allow/deny/needs-review states and provenance-backed handoff.

How to use it

Copy, assign owners, then attach real evidence.

A checklist is useful only if each item has an owner and a verifiable state. Do not mark an item complete because a tool returned a green badge.

- [ ] SBOM format/version validated
- [ ] Component identity normalised
- [ ] Licence expression parsed where available
- [ ] Allow/deny/needs-review policy applied
- [ ] Human dispositions recorded for ambiguous components
- [ ] Input/tool provenance included in final evidence pack

Checklist

What complete should mean.

01

SBOM format/version validated

02

Component identity normalised

03

Licence expression parsed where available

04

Allow/deny/needs-review policy applied

05

Human dispositions recorded for ambiguous components

06

Input/tool provenance included in final evidence pack

Scope discipline

The template is an operating aid, not certification.

Use the checklist to structure evidence, ownership and review. It does not replace the authoritative system, regulator, specialist audit, legal advice or professional judgement that may apply to the underlying job.

  • Not a legal opinion or licence clearance
  • Not a vulnerability scanner or CVE-coverage claim
  • No arbitrary remote clone/build, uploaded-code execution or CRA certification