Header simple bg

Reports for Open Source Components

Dynatrace provides cryptographically signed Software Bill of Materials (SBOMs) and license notice files for selected products, with more being added over time.

Our SBOMs follow the CycloneDX standard and contain detailed, machine-readable inventories of every software component and dependency bundled within an artifact. They enable effective vulnerability management, identification of license compliance issues, and support end-to-end visibility of supply chain risks.

Current SBOM Coverage

Dynatrace product SBOM How to retrieve & verify
ActiveGate Container Image (Regular & FIPS) ✅ Provided via in-toto attestation Verification Guide
ActiveGate Installer ✅ Bundled with our signed installers dynatrace-activegate-sbom.cdx.json is stored in the local ActiveGate installation folder
EdgeConnect Container Image ✅ Provided via in-toto attestation Verification Guide
Managed Installer ✅ Bundled with our signed installers Verification Guide
OneAgent Installer ✅ Bundled with our signed installers agentinstaller-sbom-external.cdx.json is stored in the local OneAgent installation folder
OneAgent Lambda Layers ✅ Bundled with our signed ZIP file sbom.cdx.json is stored in the root folder of an AWS Lambda ZIP file
Operator Container Image ✅ Provided via in-toto attestation Verification Guide
Synthetic Installer ✅ Bundled with our signed installers syntheticinstaller-sbom.cdx.json is stored in the local Synthetic installation folder

Reports by Version

Dynatrace RUM JavaScript Agent