Cloudbase Sensor Now Supports SBOM Collection and Vulnerability Visualization for PHP Packages

Cloudbase Inc. has expanded its security platform, "Cloudbase," by adding PHP package scanning and vulnerability visualization capabilities to "Cloudbase Sensor." It automatically collects package information from Composer-based PHP applications as an SBOM, enabling efficient security operations through integration with vulnerability management and risk prioritization features.
新製品NQ 85/100出典:PR Times

📋 Article Processing Timeline

  • 📰 Published: June 2, 2026 at 19:10
  • 🔍 Collected: June 2, 2026 at 10:20
  • 🤖 AI Analyzed: June 2, 2026 at 19:39 (9h 18m after Collected)
Cloudbase Inc. (Headquarters: Minato-ku, Tokyo; CEO: Koya Iwasa) has announced that it has expanded the functionality of its domestic security platform, "Cloudbase," by adding a new PHP package scanning feature to its Cloudbase Sensor.

With this feature, environments that have deployed Cloudbase Sensor can now automatically collect package information used in PHP applications as an SBOM (Software Bill of Materials) and continuously visualize related vulnerabilities.

## Development Background

Interest in software supply chain risk has been growing in recent years. Consequently, the importance of continuously tracking and managing the vulnerabilities of OSS packages and libraries in use is increasing. In the PHP ecosystem, which is widely used in Web application development, dependency management using Composer is common, making the tracking of library vulnerabilities a critical challenge in security operations.

Furthermore, customers have expressed a need to "visualize OSS usage status in PHP applications" and "perform integrated vulnerability management."

Against this backdrop, we have added automated PHP package information collection to Cloudbase Sensor, enabling vulnerability management utilizing SBOM.

## Update Details

In this update, Cloudbase Sensor can now automatically scan PHP package metadata on target systems and collect it as an SBOM.

This allows for the visualization of library information used in Composer-based PHP applications, and related vulnerabilities can be managed continuously on Cloudbase.

Collected SBOM information integrates with the vulnerability management and risk prioritization features provided by Cloudbase, allowing centralized confirmation of vulnerability impact and response priority.

Information collected:
- Package name
- Version
- License information
- Dependency relationships between packages
- PURL (Package URL)
- Package location path
- PHP-related package vulnerabilities display
- Software tab in resource details

## Expected Effects

By integrating with Cloudbase's vulnerability management and risk prioritization features, efficient operations based on response priority can be realized.

- Automatically collect OSS package information used in PHP applications as an SBOM and continuously visualize it
- Centrally manage vulnerabilities in Composer-based PHP applications
- Quickly identify affected packages and systems when vulnerabilities are discovered, reducing investigation and response man-hours

Furthermore, because it can integrally manage SBOM and vulnerability information across multi-language environments including Java, Python, PHP, and Node.js, it supports continuous risk management against software supply chain risks.

Cloudbase will continue to realize integrated asset and vulnerability management across cloud and on-premise environments, contributing to the strengthening of security governance for the entire organization.

FAQ

Cloudbase Sensorの今回のアップデートは何ですか?

PHPパッケージのスキャン機能が追加されました。これにより、PHPアプリケーションで利用されているパッケージ情報をSBOMとして自動収集し、関連する脆弱性を継続的に可視化できるようになりました。

収集されるPHPパッケージ情報の詳細は何ですか?

パッケージ名、バージョン、ライセンス情報、パッケージ間の依存関係、PURL(Package URL)、およびパッケージの所在パスが収集されます。

本機能によってどのような運用効率化が期待できますか?

脆弱性発見時に、影響を受けるパッケージやシステムを迅速に特定できるため、調査や対応にかかる工数の削減が期待できます。また、リスク優先度評価機能と連携し、効率的な対応運用が可能になります。

他の言語のパッケージも管理できますか?

はい。Java、Python、PHP、Node.jsを含む複数言語環境のSBOMおよび脆弱性情報を統合的に管理可能です。

Cloudbaseはどのようなセキュリティプラットフォームですか?

AWS、Azure、Google Cloud、Oracle Cloudといったマルチクラウド環境およびオンプレミス環境におけるリスクを統合的に監視・管理できるセキュリティプラットフォームです。