Evidence ledger / verified 1 September 2026

Source register

Official evidence used for product and standard claims. Vendor marketing was treated as vendor-reported, not independent proof.

Tool documentation

  1. S01 / Cisco AI BOMOfficial repository

    Release 1.10.0 was published 17 August 2026. The evidence covers source, container and cloud discovery. It also establishes supported languages, AI component categories, outputs and LLM prerequisites.

  2. S02 / Trusera ai-bomOfficial repository

    Release v3.1.0 and the repository documentation establish scanner surfaces, output formats, GitHub and GitLab integration, threshold policies and Cedar gates.

  3. S03 / AIBoMGen CLIOfficial repository

    Release v0.2.1 and the active main branch document Hugging Face discovery, CycloneDX output, validation, completeness, enrichment, security-scan import and SBOM merge.

  4. S04 / OWASP AIBOM GeneratorOfficial project page

    The page establishes input scope, JSON download, visualization, completeness scoring and standards statements.

  5. S05 / OWASP hosted toolOfficial Hugging Face Space

    Commit 6165ba9ef889951dc0fc5065a3cc65c45bc01f63 was last modified 12 March 2026. The Space verifies current public availability and hosting identity.

  6. S06 / Mend AI-BOM reportOfficial documentation

    The documentation defines report scope, entity types, CycloneDX 1.7 and SPDX 3.0.1 exports, API paths, entitlements and explicit limitations.

  7. S07 / Mend AI release notesOfficial release notes

    The 24 August 2026 release records feature timing, metadata-only export, entity triage, suppression and audit trail.

Standards and field semantics

  1. S08 / CycloneDX ML-BOMOfficial capability documentation

    This source defines model, dataset, dependency, provenance and ML-BOM semantics. The CycloneDX 1.7 specification was checked separately for model cards, formulation, declarations, claims and evidence.

  2. S09 / SPDX 3.0.1 AI ProfileOfficial specification

    This specification defines AI profile scope and conformance semantics.

  3. S10 / Implementing AI BOM with SPDX 3.0Linux Foundation Research report

    The report maps AI and Dataset profile fields to model cards and FactSheets and records profile gaps.

Publisher context

  1. S11 / AI supply chain security article

    Publisher engineering context for model-poisoning response, immutable hashes, serialization and the service-method statement. It is not used as evidence for third-party product capabilities.

Machine-readable register

The complete record, including type, scope, version and last-verification date, is available as sources.json. Claim-to-source mappings are available as claims.json.

Return to the comparison