FAQ
Vulnerability Management
How do I import vulnerability statuses from one version to another?
Why does the vulnerability import wizard show no CVEs to import?
Can vulnerability status import be automated when a new SBOM version is uploaded?
Why does vulnerability import fail when the SBOM generator changes between versions?
Why is the vulnerability count different between Interlynk and NVD for the same component?
Why does the vulnerability count at the product level double-count vulnerabilities from parts?
How do I filter for unique/deduplicated CVEs across a product with multiple parts?
What does "Incomplete Only" filter mean in the vulnerabilities view?
Why is a known vulnerability (e.g., from GitHub Security Advisories) not showing up for my component?
How do I create a custom vulnerability when one is missing from the platform?
What is the difference between EPSS Score and EPSS Percentile?
How does Interlynk handle CVSS v3.1 vs CVSS v4.0 scoring?
Why is the NVD link missing or broken for some vulnerabilities?
When does Interlynk detect a new CVE — at SBOM import time or when the CVE gets a CPE assignment?
SBOM Upload & Management
Why is my SBOM upload failing with a validation error?
Why is the SBOM upload delayed or not processing?
How do I merge multiple SBOMs together using sbomasm?
What SBOM formats does Interlynk support?
API & CLI (pylynk)
Where can I find the API documentation for Interlynk?
Why do I get an "Invalid project" error when uploading via pylynk?
What is the difference between projectGroup and project in the API?
How do I create a new build version for a product via the API?
How do I get an API security token?
How do I create component relationships via the API?
Notifications
Why am I not receiving email notifications for new vulnerabilities?
Why am I receiving notifications for projects I haven't subscribed to?
Permissions & Roles
How do I allow developers to create API tokens without giving them full organization settings access?
Why is my custom role's permissions not working as expected?
Components & Support Status
How is "Direct" dependency defined for support level analysis?
Why is a component showing "Unknown" support status when it is actively maintained?
Can I set support status at the parent product level and have it propagate to parts?
Why does the support status CSV export exclude components from parts?
PURL & Component Identity
How should I format the PURL for non-standard version strings?
What PURL type should I use for components not on standard package managers?
SBOM Features
How do I add hashes to a component for regulatory submissions (e.g., FDA)?
What does "Redact internal components" do when downloading an SBOM?
Can I exclude internal components from an SBOM export entirely?
Products & Environments
Why are my products or SBOMs not visible after upload?
How do I compare two versions across different environments?
CI/CD Integration
Where can I view CI/CD metadata sent during pylynk upload?
How do I upload SBOMs from Azure DevOps pipelines?
General
What is an SBOM?
How often are vulnerability scans run?
Can I export my data from Interlynk?
Is there a rate limit on the API?
How do I request a new feature?
Last updated