Microsoft Defender for Cloud
Cloud and workloads

Query software bill of materials (SBOM)

In brief

The article now describes querying repository and package data in the cloud security graph, adds a prerequisite note, updates the heading anchor, and refreshes metadata.

What Defender admins need to know

Administrators get clearer context and navigation when preparing package queries; review the listed prerequisites before building one.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Query software bill of materials (SBOM)

Microsoft Defender for Cloud's DevOps Security agentless scanning capabilities automatically generate a Software Bill of Materials (SBOM) for connected code repositories. When a scan finishes, the process publishes the repository and identified packages to the cloud security graph.

You can use Defender for Cloud's cloud security explorer to query this data.the repository and package data in the cloud security graph. By using the cloud security explorer, you can locate specific packages (dependencies) and identify exactly which repositories use them. Use this informationthe query results to identify the impact radius of a vulnerable package version across your organization.

Prerequisites

Before you build a package query, make sure the following prerequisites are met:

  • Enable agentless scanning in your DevOps connector.
  • Wait for the initial scan to complete so the Software Bill of Materials (SBOM) data is populated in the Cloud Map.

Build a package query

By using the cloud security explorer,Cloud Security Explorer in Microsoft Defender for Cloud, you can build a query to find repositories that include specific packages (dependencies) and versions.

  1. Sign in to the Azure portal.

The query runs and all repositories containing the specified package and version are presented. Select a repository from the results to view further details about the installed software and its security posture.

Next stepsteps

[!div class="nextstepaction"] Common questions about DevOps Security