A CVE is a query,
not a war room.
Supplier SBOMs land on the architecture, not in a folder. When a CVE publishes, the route — component → software unit → ECU → project → vehicle — is already wired. You answer in minutes, with the evidence chain attached.
SBOMs as delivered.
Diffed, not overwritten.
CycloneDX and SPDX per software unit, versioned per baseline. Re-imports diff against the last delivery — 12 new components is a changelog entry, not a mystery.
Watched continuously.
Triaged by position.
Components are matched against vulnerability feeds around the clock. Priority comes from where a component sits in the architecture — not CVSS alone.
CVE → component →
ECU → vehicle. One query.
The match lands on the graph, so blast radius is computed: which software units, which projects, which programs. Suppliers get a share request, not an email thread.
VEX with the proof
built in.
Not-affected statements carry their justification from the graph. We publish our own platform SBOM the same way — see the Trust Center.