FossID is pleased to announce version 24.1 of its Software Composition Analysis (SCA) application, Workbench. This release brings various enhancements requested by our clients and team of auditors, including improvements to SBOM management, API and Product documentation, and expanded scope of its governance capabilities.
SBOM Management
Producing a complete Software Bill-of-Materials (SBOM) is a core focus of Workbench, requiring updates to match evolving legislative requirements and changes to standard formats. In this release, Workbench expands its support for the SPDX and CycloneDX SBOM formats:
- SPDX: Improved support for SPDX 2.3, adding the built date field to exported SBOMs and adding the ability to import the download location and supplier fields when importing SBOMs.
- CycloneDX: importing CycloneDX 1.5 SBOMs is now supported. We’ve also added support for importing component metadata from the sha1, sha-256, and md5 fields, helping users migrate component identifications by importing a CycloneDX SBOM with those fields.
Documentation Improvements
Based on user feedback we’re excited to announce improvements to our product and API Documentation.
- The Workbench API documentation has been rewritten to use the OpenAPI Spec, helping clients better understand our endpoints and API responses.
- The Product Documentation also went through a redesign, with a new sidebar experience for easier navigation.
Both areas were hot requests by our clients, and there is more work to be done as we continuously improve them. Please let us know what you think of the changes so far!
Governance
Our Component Approval workflow has been expanded to also include Managed Open Source discovered through Dependency Analysis. Auditors can now create and process Component Approval requests for Managed Open Source, which are reflected in the Excel report.
Upgrade Today
FossID clients can take advantage of the new enhancements by accessing the Delivery Portal, downloading the new version, and upgrading their Workbench to version 24.1. Please let the FossID team at (support@fossid.com) if you have any questions.