Get started¶
There are two ways into alloy-it, and which one you want depends on the job in front of you.
-
You are responsible for what your company placed on the EU market and for the Article 14 reporting duty that starts on 11 September 2026.
You will create products, record the releases you shipped, and fill in your reporter identity. No SBOM required to begin.
Best for: product security, PSIRT, compliance, engineering leads.
-
You need a toolchain that installs identically on your machine, your colleague's machine, and CI, and that can be reconstructed years later.
You will install
alloy-provisionerand pull a blueprint.Best for: embedded and platform engineers, CI owners.
Not sure?¶
| If you are trying to… | Start with |
|---|---|
| Answer "which products contain this CVE?" | CRA operations |
| Be ready to file a 24-hour report in September | CRA operations |
| Produce evidence for an assessor or a customer questionnaire | CRA operations |
| Stop losing a day to toolchain setup on every new project | Build environments |
| Make CI use the same toolchain as local development | Build environments |
| Patch a release built four years ago | Build environments, then link it as provenance |
Most organisations end up doing both. They connect through provenance: a release records which blueprint built it, so when triage says a shipped release is affected, you have a rebuild target instead of an investigation.
What you need¶
For CRA operations: an account on the dashboard. Community tier is free; product inventory, triage, reporting, advisories, and evidence require a Team or Enterprise plan and membership of an organisation.
For build environments: a Linux environment (native, WSL2, a VM, or a container) with
curl or wget, apt, and sudo. See
before you start.
Then what?¶
Once you are set up, the rest of the documentation follows the work:
Products and releases → SBOMs → Monitoring → Triage → Reporting → Advisories → Evidence