For the full picture of how this feature works — data model, AI agents, VEX outputs, compliance — see Vulnerability Management and Risk Assessment.
What you’re wiring up
Your CI produces the inputs; Chainloop does the rest:Pieces of Evidence Used
Only the vulnerability report is required. The other two are optional but unlock additional views and traceability.
A CycloneDX SBOM that carries vulnerabilities can cover the vuln-report and SBOM inputs in one file. Without an artifact reference, Chainloop uses the one declared inside the SBOM, but it won’t be tied to an attested build.
The full list of accepted material types and the policies that consume them lives in the vulnerabilities policy reference.
1. Instrument your CI to populate the Security tab
Wire your CI/CD pipeline to attest the vulnerability report (and any optional materials). Once the workflow runs, the Security tab fills in.Prerequisites
- A Chainloop project and workflow for the artifact you want to track
- A vulnerability report in one of the supported formats listed above (Trivy and Grype produce these out of the box)
- Optional but recommended: an SBOM (CycloneDX JSON or SPDX JSON) to populate the Components view, and a container image reference from your build so findings trace back to a specific attested build output
Add the policy group to your contract
Reference the built-invulnerability-management policy group in your workflow contract:
chainloop.contract.yaml
Attest your materials
Inside your CI/CD pipeline, initialize an attestation, add the vulnerability report (plus any optional materials), and push it to Chainloop:If your SBOM already contains vulnerability data (a CycloneDX file with both components and vulnerabilities), you can skip the separate
vuln-report attestation. Chainloop extracts findings directly from the SBOM.Run the workflow
After the first run lands and the policy evaluates the evidence, the Security tab fills in:- Components as soon as the SBOM is parsed
- Vulnerabilities when the scan report runs through the policy
- Artifacts under the image reference
- Reports with PDFs and VEX once you approve assessments
2. Perform your first risk assessment
With findings flowing into the Security tab, walk through the triage loop end-to-end on a single CVE so you’ve seen every step before scaling up.- Open Overview and check the unassessed Critical/High count.
- Click View Unassessed to land on the filtered Vulnerabilities list.
- Open a finding and write (or accept the agent’s draft) assessment.
- Approve the assessment. The finding moves out of the active backlog.
- Share the auto-generated VEX feed URL with your customers and control gates.
Going further
- Attach a compliance framework to your product — for example, the Cyber Resilience Act (CRA), SSDF, or your own best-practices framework — so the same SBOMs, scanner reports, and assessments drive your compliance posture automatically
- Enable the Vulnerabilities Agent to draft assessments automatically (Preview)
- Wire notifications to Slack, Teams, or email
- Update your control-gate policies to read assessments, so dismissed findings stop blocking the release
- Learn more about Vulnerability Management and Risk Assessment — the data model, AI agents, VEX outputs, and compliance mapping
Troubleshooting and FAQ
I don't see any vulnerabilities
I don't see any vulnerabilities
Two things to check:
- Confirm your vulnerability report is being evaluated by the built-in
vulnerability-managementpolicy group. Vulnerabilities only surface when a policy parses the report — without it, the material is attested but not turned into findings. - Make sure you’re on the Enterprise Edition CLI v1.73.0 or later. Earlier versions don’t emit findings into the Security tab.
I don't see any components
I don't see any components
Components are extracted from the SBOM. If the Components view is empty, your attestation is missing an SBOM material — add a
SBOM_CYCLONEDX_JSON (or SBOM_SPDX_JSON) to the run and re-attest.