# SBOM Examples (/docs/content-requirements/examples)

These compact examples follow the content requirements outlined in this documentation and demonstrate different real-world use cases. Each document is a complete, valid JSON file that shows how to structure metadata, components, dependencies, and vulnerability information according to industry standards.

The examples include a healthcare application scenario with proper supplier identification, patched dependencies, vendor-provided components, and redacted firmware. While production SBOMs typically contain many more components, these examples focus on demonstrating key patterns and requirements in a readable format.

## Download examples [#download-examples]

<Cards>
  <Card icon="<Download />" title="CycloneDX SBOM" href="/examples/cyclonedx-sbom.json" description="Complete CycloneDX 1.6 SBOM showing metadata, components, dependencies, compositions, and build tools" />

  <Card icon="<Download />" title="SPDX SBOM" href="/examples/spdx-sbom.json" description="Complete SPDX 2.3 SBOM demonstrating packages, files, relationships, and annotations" />

  <Card icon="<Download />" title="CSAF VEX" href="/examples/csaf-vex.json" description="CSAF 2.0 VEX document showing vulnerability status communication and product relationships" />
</Cards>

## What's inside [#whats-inside]

Each example demonstrates:

* **Required metadata**: unique identifiers, timestamps, supplier information, and tool documentation
* **Component inventory**: properly identified components with PURLs, hashes, and licenses
* **Dependency relationships**: both direct and transitive dependencies structured as hierarchies
* **Advanced scenarios**: patched components, vendor-provided SBOMs, incomplete assemblies, and redacted information
* **Vulnerability handling**: (VEX only) vulnerability status, impact analysis, and remediation guidance