| Cluster | Present | Gap | Review | Total |
|---|---|---|---|---|
| Metadata | 7 | 3 | 0 | 10 |
| System Level Properties | 4 | 1 | 4 | 9 |
| Models | 14 | 0 | 0 | 14 |
| Datasets Properties | 8 | 0 | 2 | 10 |
| Infrastructure | 0 | 2 | 0 | 2 |
| Security Properties | 0 | 1 | 3 | 4 |
| Key Performance Indicators | 0 | 1 | 1 | 2 |
| Total | 33 | 8 | 10 | 51 |
| # | Status | Requirement | Required | Detail | Evidence / how |
|---|---|---|---|---|---|
| 1 | PASS | Spec version (CycloneDX 1.3/1.4/1.5/1.6/1.7) | yes | CycloneDX 1.7 | |
| 2 | PASS | Timestamp (metadata.timestamp) | yes | 2026-07-22T07:05:10+00:00 | |
| 3 | PASS | Tool info (metadata.tools) | yes | 1 tool(s) | |
| 4 | PASS | Top-level component name+version | yes | job-2026-07-22-07:05:10@1.0 | |
| 5 | PASS | Component name+version coverage (100%) | yes | 1/1 | |
| 6 | PASS | PURL coverage (>= 90%) | yes | 100% (1/1) | |
| 7 | PASS | Traceable PURL (no pkg:generic, advisory) | no | 0 untraceable | |
| 8 | PASS | PURL syntax (pkg:type/[namespace/]name) | yes | 0 malformed | |
| 9 | PASS | Transitive dependencies (graph edges) | yes | 8 edge(s) | |
| 10 | WARN | License coverage (>= 80%, recommended) | no | 62% (5/8) | |
| 11 | PASS | Hash coverage (>= 50%, recommended) | no | 100% (8/8) |
| # | Status | Requirement | Detail | Evidence / how |
|---|---|---|---|---|
| 1 | WARN | SBOM author | not present in the SBOM | |
| 2 | PASS | SBOM version | present | |
| 3 | PASS | SBOM data format name | present | |
| 4 | PASS | SBOM data format version | present | |
| 5 | WARN | SBOM author signature | not present in the SBOM | How to fill this |
| 6 | PASS | SBOM tool name | present | |
| 7 | PASS | SBOM tool version | present | |
| 8 | WARN | SBOM generation context | not present in the SBOM | |
| 9 | PASS | SBOM timestamp | present | |
| 10 | PASS | SBOM dependency relationship | present | |
| 11 | PASS | System name | present | |
| 12 | PASS | System components | present | |
| 13 | WARN | System producer | not present in the SBOM | |
| 14 | PASS | System version | present | |
| 15 | PASS | System timestamp | present | |
| 16 | REVIEW | System data flow | requires human review (no automated source) | What to establishWrite down how data moves through the system: where an input comes from, what the model receives, and where its output goes. Confirm the description matches how the system is actually deployed. |
| 17 | REVIEW | System data usage | requires human review (no automated source) | What to establishState what the system does with the data it receives — whether it is stored, passed to another component, or used for further training. Check this against the privacy notice you publish. |
| 18 | REVIEW | System input/output properties | requires human review (no automated source) | What to establishDescribe the input and output the system accepts and produces — formats, size limits, and anything it refuses. A person confirms this because a model card lists modalities, not the system's actual interface. |
| 19 | REVIEW | Intended application area | requires human review (no automated source) | What to establishState the field the system is intended for and the uses that are out of scope. This is a decision, not a fact a tool can read, and regulators ask for it directly. |
| 20 | PASS | Model name | 1/1 model component(s) | |
| 21 | PASS | Model identifier | 1/1 model component(s) | pkg:huggingface/FINAL-Bench/Aether-7B-5Attn@613b24f7 |
| 22 | PASS | Model version | 1/1 model component(s) | |
| 23 | PASS | Model timestamp | 1/1 model component(s) | |
| 24 | PASS | Model producer | 1/1 model component(s) | |
| 25 | PASS | Model description | 1/1 model component(s) | |
| 26 | PASS | Model hash value | 1/1 model component(s) | |
| 27 | PASS | Model hash algorithm | 1/1 model component(s) | SHA-256 |
| 28 | PASS | Model properties (model card) | 1/1 model component(s) | aether_v2_7way |
| 29 | PASS | Model input-output properties | 1/1 model component(s) | |
| 30 | PASS | Model training properties | 1/1 model component(s) | |
| 31 | PASS | Model license | 1/1 model component(s) | Apache-2.0 |
| 32 | PASS | Model license — openness (weight/architecture/data/training) | present | open-architecture, open-data, open-training, open-weight, openness:architecture=open-architecture, openness:training-data=open-data, openness:training=open-training, openness:weights=open-weight |
| 33 | PASS | Model external references | 1/1 model component(s) | |
| 34 | PASS | Dataset name | present | HAERAE-HUB/KOREAN-SyntheticText-1.5B, HAERAE-HUB/KOREAN-WEBTEXT, HuggingFaceFW/fineweb-edu, HuggingFaceTB/finemath, HuggingFaceTB/smollm-corpus, OpenCoder-LLM/opc-fineweb-code-corpus, open-web-math/open-web-math |
| 35 | PASS | Dataset description | present | |
| 36 | PASS | Dataset content | present | |
| 37 | PASS | Dataset identifier | present | |
| 38 | PASS | Dataset hash | present | |
| 39 | PASS | Dataset provenance | present | |
| 40 | REVIEW | Dataset statistical properties | requires human review (no automated source) | What to establishGive the size and shape of the training data — record counts, class balance, and any known skew. These numbers explain the model's limits, so state them even when they are unflattering. |
| 41 | REVIEW | Dataset sensitivity (PII/copyright) | requires human review (no automated source) | What to establishJudge whether the training data holds personal information or third-party copyrighted work, and record what you filtered out and how. Where the answer is unclear, take it to your privacy and legal contacts before release. |
| 42 | PASS | Dataset dependency relationship | present | |
| 43 | PASS | Dataset license | present | |
| 44 | WARN | Infrastructure software (dependencies) | not present in the SBOM | |
| 45 | WARN | Infrastructure hardware (HBOM link) | not present in the SBOM | How to fill this |
| 46 | REVIEW | Security controls | requires human review (no automated source) | What to establishList the controls that protect the model and its data — who can reach the weights, how the training environment is isolated, how artefacts are signed. These live in your operations, not in the SBOM. |
| 47 | REVIEW | Security compliance | requires human review (no automated source) | What to establishName the security standard or internal policy this model was built under, and who signed off. Point at the assessment record rather than restating it here. |
| 48 | REVIEW | Cybersecurity policy information | requires human review (no automated source) | What to establishGive the route for reporting a vulnerability in this model and who answers it. A published model needs a contact that outlives the person who trained it. |
| 49 | WARN | Vulnerability referencing | not present in the SBOM | |
| 50 | REVIEW | Security metrics | requires human review (no automated source) | What to establishRecord what you measured on the security side — adversarial or jailbreak testing, refusal rates, red-team results — with the method and the date. If nothing was measured, say so plainly. |
| 51 | WARN | Operational performance KPIs | not present in the SBOM |
| # | Status | Requirement | Detail | Evidence / how |
|---|---|---|---|---|
| 1 | PASS | System name | present | |
| 2 | REVIEW | System data flow | requires human review (no automated source) | What to establishWrite down how data moves through the system: where an input comes from, what the model receives, and where its output goes. Confirm the description matches how the system is actually deployed. |
| 3 | REVIEW | System data usage | requires human review (no automated source) | What to establishState what the system does with the data it receives — whether it is stored, passed to another component, or used for further training. Check this against the privacy notice you publish. |
| 4 | REVIEW | System input/output properties | requires human review (no automated source) | What to establishDescribe the input and output the system accepts and produces — formats, size limits, and anything it refuses. A person confirms this because a model card lists modalities, not the system's actual interface. |
| 5 | REVIEW | Intended application area | requires human review (no automated source) | What to establishState the field the system is intended for and the uses that are out of scope. This is a decision, not a fact a tool can read, and regulators ask for it directly. |
| 6 | PASS | Model description | 1/1 model component(s) | |
| 7 | PASS | Model properties (model card) | 1/1 model component(s) | |
| 8 | PASS | Model input-output properties | 1/1 model component(s) | |
| 9 | PASS | Model training properties | 1/1 model component(s) | |
| 10 | PASS | Dataset name | present | |
| 11 | PASS | Dataset description | present | |
| 12 | PASS | Dataset content | present | |
| 13 | PASS | Dataset provenance | present | |
| 14 | REVIEW | Dataset statistical properties | requires human review (no automated source) | What to establishGive the size and shape of the training data — record counts, class balance, and any known skew. These numbers explain the model's limits, so state them even when they are unflattering. |
| 15 | REVIEW | Dataset sensitivity (PII/copyright) | requires human review (no automated source) | What to establishJudge whether the training data holds personal information or third-party copyrighted work, and record what you filtered out and how. Where the answer is unclear, take it to your privacy and legal contacts before release. |
| 16 | PASS | Dataset license | present | |
| 17 | WARN | Infrastructure software (dependencies) | not present in the SBOM | |
| 18 | WARN | Infrastructure hardware (HBOM link) | not present in the SBOM | How to fill this |
| 19 | REVIEW | Security controls | requires human review (no automated source) | What to establishList the controls that protect the model and its data — who can reach the weights, how the training environment is isolated, how artefacts are signed. These live in your operations, not in the SBOM. |
| 20 | REVIEW | Cybersecurity policy information | requires human review (no automated source) | What to establishGive the route for reporting a vulnerability in this model and who answers it. A published model needs a contact that outlives the person who trained it. |
| 21 | WARN | Vulnerability referencing | not present in the SBOM | |
| 22 | REVIEW | Security metrics | requires human review (no automated source) | What to establishRecord what you measured on the security side — adversarial or jailbreak testing, refusal rates, red-team results — with the method and the date. If nothing was measured, say so plainly. |
| 23 | WARN | Operational performance KPIs | not present in the SBOM |
| # | Status | Requirement | Detail | Evidence / how |
|---|---|---|---|---|
| 1 | PASS | System name | present | |
| 2 | REVIEW | System data flow | requires human review (no automated source) | What to establishWrite down how data moves through the system: where an input comes from, what the model receives, and where its output goes. Confirm the description matches how the system is actually deployed. |
| 3 | REVIEW | System data usage | requires human review (no automated source) | What to establishState what the system does with the data it receives — whether it is stored, passed to another component, or used for further training. Check this against the privacy notice you publish. |
| 4 | REVIEW | Intended application area | requires human review (no automated source) | What to establishState the field the system is intended for and the uses that are out of scope. This is a decision, not a fact a tool can read, and regulators ask for it directly. |
| 5 | PASS | Model training properties | 1/1 model component(s) | |
| 6 | REVIEW | Dataset sensitivity (PII/copyright) | requires human review (no automated source) | What to establishJudge whether the training data holds personal information or third-party copyrighted work, and record what you filtered out and how. Where the answer is unclear, take it to your privacy and legal contacts before release. |
| 7 | REVIEW | Security controls | requires human review (no automated source) | What to establishList the controls that protect the model and its data — who can reach the weights, how the training environment is isolated, how artefacts are signed. These live in your operations, not in the SBOM. |
| 8 | REVIEW | Cybersecurity policy information | requires human review (no automated source) | What to establishGive the route for reporting a vulnerability in this model and who answers it. A published model needs a contact that outlives the person who trained it. |
| 9 | WARN | Vulnerability referencing | not present in the SBOM | |
| 10 | REVIEW | Security metrics | requires human review (no automated source) | What to establishRecord what you measured on the security side — adversarial or jailbreak testing, refusal rates, red-team results — with the method and the date. If nothing was measured, say so plainly. |