An SBOM lists every component in your software β the basis for answering 'are we affected?' when the next Log4Shell appears. We automatically generate an SBOM (CycloneDX + SPDX) per repo at scan time and run dependency audit on top.
Run a free domain scan All checks βWe automatically generate an SBOM in CycloneDX and SPDX format (via syft) from every repo at scan time, and run dependency audit (pip-audit / npm audit) incl. transitive dependencies on top. The component count and formats are shown in the report, so you can quickly answer whether a new CVE affects you.
When a critical vulnerability in a widely-used dependency is published, the first question is 'do we use it, and where?'. Without an SBOM that takes days. With one it takes minutes β and it's increasingly a supply-chain requirement.
What's the difference from dependency scanning?
We do both: generate a full SBOM (to answer FUTURE vulnerabilities) AND run dependency audit (for today's known CVEs) on top.
What format?
CycloneDX and SPDX (JSON), generated per repo with syft. We also deliver vulnerability analysis of your dependencies on top.
Does it run self-hosted?
Yes β the dependency audit can run in your environment.
Run a free scan or order a full Security Assessment β prioritised, not noise.
Run a free domain scan