Install

Works with Drupal: ^10 || ^11

Using dev releases is not recommended, except for testing.

Using Composer to manage Drupal site dependencies

Alternative installation files

Download tar.gz 17.95 KB
MD5: 79bd9403f7206b07d95bba3bb7617485
SHA-1: 6254d1479eb5a5f98b39b2cf902e52b93b88805c
SHA-256: 9a4db66ff606a79a01309e1dc6fd9c8690c0323c3ce2beef5f1cf1c92b86d07e
Download zip 25.05 KB
MD5: 7343a2d23454cae4b37c2c033b451900
SHA-1: 30ded77e265927c24003b9bd08f374a511c1ea26
SHA-256: baa106580d0db84637ea4f2d8965207a6784b42f418e49c3af9c1a12f2047554

Release notes

First release of the Drupal on-ramp for Proofwright CRA evidence.

Builds a CycloneDX 1.5 SBOM of Drupal core, contrib and custom extensions, and sends it to your Proofwright console over HTTPS. Components are mapped to Composer package URLs, so known vulnerabilities are recognised automatically once the SBOM lands.

Sending is opt-in — nothing leaves the site until a licence key and console URL are configured. It can run on cron or on demand from the settings form.

Requires Drupal 10 or 11 and PHP 8.1+.

Created by: 1click2open
Created on: 5 Aug 2026 at 14:40 UTC
Last updated: 6 Aug 2026 at 10:17 UTC
New features

Other releases