CycloneDX Tool Center

Explore the largest marketplace of tools and solutions designed to optimize and secure the software supply chain.

Showing 257 tools
Abom
Vulert.com

Web SCA service that analyzes CycloneDX or SPDX SBOMs (or lockfiles) to flag open-source vulnerabilities and license issues, sending real-time alerts without requiring code access or signup.


Supported Languages: N/A
Availability: Freemium
Lifecycle: Post Build , Operations
action-owasp-dependecy-track-check
Quobis

GitHub Action that builds a CycloneDX SBOM for Node.js, Python, Go, Ruby, Java, .NET and PHP projects, converts it to v1.2 when necessary, and uploads it to an OWASP Dependency-Track server for automatic vulnerability analysis.


Supported Languages: Node.js , Python , Go , Ruby , Java , .NET , PHP , Javascript
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
AI SBOM (AIBOM, ML-BOM) Generator
Aetheris AI

Generate AI SBOM (AIBOM, AI/ML-BOM) in CycloneDX format for models on Hugging Face.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build
Amazon Inspector SBOM Generator
Amazon Inspector

Amazon Inspector SBOM Generator (inspector-sbomgen) outputs CycloneDX 1.4 or SPDX 2.3 SBOMs for archives, container images, directories, local systems, and Go/Rust binaries, providing metadata for vulnerability scans with the Inspector ScanSBOM API.


Supported Languages: Go , Java , Javascript , .NET , PHP , Python , Ruby , Rust
Availability: Subscription
Lifecycle: Post Build
Apiiro
Apiiro

Application Security Posture Management (ASPM) platform that proactively identifies and remediates critical risks in cloud-native applications across the software supply chain.


Supported Languages: Javascript , Java , Python , Go , .NET , Rust
Availability: Commercial License
Lifecycle: Design , Pre Build , Build , Post Build
apko
Chainguard

Build OCI images using APK directly without Dockerfile. Generates CycloneDX SBOMs for containers using native SBOM functionality in apk-tools v3.0 and higher.


Supported Languages: C/C++ , Go , Python , Rust
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
apt2sbom
Eliot Lear

Python tool that builds a Software Bill of Materials (SBOM) from APT and Python package information on Ubuntu systems, with CLI and HTTP interfaces.


Supported Languages: Python
Availability: OSI Approved
Lifecycle: Discovery , Operations
Arnica
Arnica

SaaS platform that automates software supply-chain security; offers free, always-up-to-date SBOM generation in CycloneDX format plus risk analysis and CI/CD integrations.


Supported Languages: N/A
Availability: Freemium , Subscription
Lifecycle: Build , Operations
Arsenal
Deepbits

Free online toolset that builds AI-powered SBOMs and SaaSBOMs for COTS, OSS, code repos and container images, then analyzes vulnerabilities, licenses and outdated components to surface software-supply-chain risk.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby
Availability: Freemium , Commercial License
Lifecycle: Build , Post Build , Discovery
asdf-cyclonedx
Xeed.IO, LLC

asdf plugin that installs and manages CycloneDX CLI versions, enabling SBOM tooling in any asdf-managed environment.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Build
Athena
Medical Aegis Inc

Athena is a SaaS solution for medical device makers that overlays the product development lifecycle to address risks before devices go to market.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift , Erlang Elixir , Scala , Kotlin , Groovy , Fortran
Availability: Commercial License
Lifecycle: Design , Pre Build , Build , Post Build , Operations , Discovery , Decommission
Auditjs
Sonatype

Audits JavaScript projects to identify known vulnerabilities and outdated package versions using the OSS Index v3 REST API


Supported Languages: Javascript
Availability: Open Source
Lifecycle: Build
Beniva Software Bill of Materials (SBOM)
Beniva

Beniva SBOM allows you to consume CycloneDX SBOM and Vulnerability Exploitability eXchange (VEX) within the ServiceNow platform which increases visibility of vulnerabilities and reduces time to remediate.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Operations
Bitbucket Pipe for SBOM Generation
ShiftLeftCyber

Integrate this Bitbucket Pipe into your CI/CD pipeline to automatically generate a Software Bill of Materials (SBOM) for any project.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift , Erlang Elixir , Scala
Availability: Open Source
Lifecycle: Build , Post Build
Black Duck
Synopsys

Black Duck is Synopsys’ SCA platform that generates CycloneDX/SPDX SBOMs, detects open-source vulnerabilities, and automates license and policy compliance across applications, containers and CI/CD pipelines.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift , Erlang Elixir , Scala , Kotlin
Availability: Subscription , Commercial License
Lifecycle: Pre Build , Build , Post Build , Operations , Discovery
BlackBerry Jarvis
BlackBerry

Software composition analysis (SCA) and security testing solution that detects and lists open-source software and licenses in embedded systems and their cybersecurity vulnerabilities and exposures.


Supported Languages: C/C++ , Java
Availability: Subscription , Commercial License
Lifecycle: Pre Build , Build , Post Build , Operations
bogrod
productaize

A command line tool to manage SBOM and VEX like source code and to distribute SBOMs to notaries.


Supported Languages: Python
Availability: OSI Approved
Lifecycle: Operations , Discovery
BOM Repository Server
CycloneDX

A lightweight repository server used to publish, manage, and distribute CycloneDX SBOMs.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Post Build , Operations
bomber
DevOps Kung Fu Mafia

CLI scanner that analyses CycloneDX, SPDX or Syft SBOMs for security vulnerabilities and licence issues using OSV, Sonatype OSS Index, GitHub Advisory or Snyk providers.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
bombon
nikstur

CLI and Nix library that generates CycloneDX v1.5 SBOMs for Nix packages, including build-time and vendored dependencies, compliant with BSI TR-03183 and US EO 14028.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
BOMnipotent
Weichwerke Heidrich Software

A server application for managing and distributing SBOMs and CSAF documents. Integrates with tools for vulnerability scanning.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Build , Post Build , Operations
BOMSkope
Netskope

BOMSkope is a Software Bill of Materials manager designed to streamline the tracking of vendor components. It enables the identification and monitoring of vulnerabilities in vendor software, enhancing visibility into your overall security posture.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Operations
build-info-go
JFrog

Open-source Go library and CLI that captures build metadata and outputs CycloneDX SBOMs for Java, Node.js, .NET, Go, Python and more.


Supported Languages: Go , Java , Javascript , .NET , Node.js , Python
Availability: Open Source
Lifecycle: Build , Post Build
Bytesafe
Bytesafe

Bytesafe is a dependency firewall and SCA platform that blocks malicious packages, scans for vulnerabilities, enforces license policies, and generates CycloneDX SBOMs to secure the software supply chain.


Supported Languages: Java , Javascript , .NET , Node.js , Python
Availability: Open Source , Freemium , Subscription
Lifecycle: Build , Operations
CaPyCli - Clearing Automation for SW360
Siemens

CaPyCli is an MIT-licensed Python CLI that generates, compares, merges and converts CycloneDX SBOMs for several language ecosystems and maps them to a SW360 component database.


Supported Languages: Java , Javascript , Python
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
CAST Highlight
CAST

CAST Highlight automatically analyzes source code portfolios for open-source risks, cloud readiness, resiliency, green impact and technical debt, and can import CycloneDX SBOMs for instant SCA insights.


Supported Languages: Java , .NET , Node.js , Javascript , C/C++ , Go , Python , PHP , Ruby , Scala , Kotlin
Availability: Subscription , Commercial License
Lifecycle: Pre Build , Build , Post Build , Operations
CAST SBOM Manager
CAST

CAST SBOM Manager automates creation, customization and maintenance of SBOMs, adds vulnerability and license insights, and exports them in CycloneDX, Excel and Word with a free tier up to 25 SBOMs.


Supported Languages: N/A
Availability: Freemium
Lifecycle: Pre Build , Post Build
CBOM Viewer
IBM

A Web Service to visualize and explore the use of cryptography in software with Cryptography Bills of Materials (CBOM).


Supported Languages: Java , Javascript , Python
Availability: Commercial License
Lifecycle: Build , Post Build , Operations
CBOMkit
IBM

CBOMkit is a toolset for generating, viewing, checking, and storing Cryptography Bills of Materials (CBOM).


Supported Languages: Java , Python
Availability: Open Source
Lifecycle: Build , Post Build , Operations
CBOMkit-theia
IBM

A tool that detects cryptographic assets in container images and directories, generating CBOMs.


Supported Languages: Java , Javascript , .NET , Python
Availability: Open Source
Lifecycle: Post Build , Operations
cdx-central
nscuro

CLI utility that downloads public CycloneDX SBOMs from Maven Central for selected artifacts.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
cdx-enrich
Michael Tsfoni

Enriches a CycloneDX Software Bills of Material (SBOM) with predefined data.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift , Erlang Elixir , Scala
Availability: Open Source
Lifecycle: Post Build
cdx-vs-cdx
marcosanchotene

GTK-style Python GUI that compares two CycloneDX JSON SBOMs, highlighting components unique to each file and those present in both.


Supported Languages: N/A
Availability: Open Source
Lifecycle: N/A
cdxgen
CycloneDX

Universal polyglot CLI, library and server that generates CycloneDX SBOMs—including SaaSBOM, OBOM and CBOM variants—for source code, container images and cloud resources.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Open Source
Lifecycle: Build , Post Build , Operations , Discovery
Chainloop
Chainloop

Chainloop is an Open Source evidence store for your Software Supply Chain attestations, SBOMs, VEX, QA reports, and more.


Supported Languages: Go , Java , Javascript , Python
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build , Operations
Checkov
Checkov

Prevent cloud misconfigurations during build-time for Terraform, Cloudformation, Kubernetes, Serverless framework and other infrastructure-as-code-languages with Checkov by Bridgecrew. Can output to CycloneDX.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Build , Pre Build , Post Build
Chelsea
Sonatype

Dependency vulnerability auditor for Ruby


Supported Languages: Ruby
Availability: Open Source
Lifecycle: Build
CodeNotary CAS
CodeNotary

CAS is an open source attestation service for the community. Notarize and authorize files, directories, git repos and Build SBOMs of containers.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build
Codenotary CAS Authenticate Docker Image and SBOM
Codenotary

A GitHub Action which authenticates notarized Docker images and SBOMs.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build
Codenotary CAS Notarize Docker Image and SBOM
Codenotary

A GitHub Action which notarizes and creates an SBOM for Docker images.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build
Codenotary vcn
Codenotary

Protects an organization's software development pipeline from supply chain attacks. Codenotary natively supports CycloneDX SBOMs.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build
CodeSentry
GrammaTech

Software Composition Analysis (SCA) platform that leverages binary analysis to identify components, inherited risk, and communicates inventory through CycloneDX SBOMs


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Post Build , Discovery
Continuous Clearing
Siemens

Scans third-party OSS components in NPM, NuGet, Maven, Python and Debian projects, generates CycloneDX SBOMs, then uploads them to SW360 and Fossology for automated license clearing.


Supported Languages: Java , Javascript , .NET , Python
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build
Contrast Security
Contrast Security

Automatically generates component inventory from runtime analysis (IAST or RASP) and generates CycloneDX SBOMs


Supported Languages: Java , Javascript , Node.js , .NET , Python , Go , PHP , Ruby
Availability: Commercial License , Subscription
Lifecycle: Build , Post Build , Operations , Discovery
Cosign
Sigstore

Container Signing, Verification and Storage in an OCI registry, including CycloneDX SBOMs


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build , Operations
Covenant
Patrik Svensson

Command-line tool that creates SBOMs from .NET and NPM projects or existing CycloneDX BOMs, outputting CycloneDX or SPDX formats.


Supported Languages: .NET , Javascript , Node.js
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
CVE Scan
The Embedded Kit

Detect and mitigate vulnerabilities in embedded systems. Generate SBOMs, cross-reference public databases, integrate with CI pipelines, and use filtering/annotations for streamlined security maintenance.


Supported Languages: C/C++ , Python , Javascript
Availability: Commercial License
Lifecycle: Build , Post Build , Operations , Discovery
cve-bin-tool
Intel

Command-line scanner that identifies vulnerable components in binaries, accepts/generates SBOMs, and reports CVEs. Supports 400+ checkers for open source libraries with CycloneDX output.


Supported Languages: C/C++ , Python , Javascript , Erlang Elixir , Go , Rust
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery
CxSCA
Checkmarx

Software Composition Analysis (SCA) platform that identifies vulnerabilities, malicious code, and license risks in open-source libraries with exploitable path analysis and SBOM generation capabilities.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Commercial License , Freemium
Lifecycle: Build , Post Build
Cybeats SBOM Studio
Cybeats Technologies Inc.

Enterprise solution to manage SBOMs at scale and proactively discover and reduce risk across the entire software supply chain, from development through deployment.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Python , Ruby , Rust
Availability: Commercial License
Lifecycle: Pre Build , Build , Post Build , Operations , Discovery
Cybellum SBOM
Cybellum Technologies LTD.

Analyzes binary artifacts to generate SBOMs including context-based analysis to perform accurate vulnerability assessment


Supported Languages: N/A
Availability: Commercial License , Subscription
Lifecycle: Post Build , Operations , Discovery
Cyberwatch
Cyberwatch

Cyberwatch Vulnerability Manager allows you to discover assets, scan and prioritize vulnerabilities, and fix them.


Supported Languages: .NET , Java , Javascript , Python
Availability: Commercial License
Lifecycle: Build , Post Build , Operations
CycloneDX .NET Generate SBOM
CycloneDX

GitHub Action to create a CycloneDX Software Bill-of-Materials (SBOM) for .NET projects supporting multiple project formats and recursive analysis


Supported Languages: .NET
Availability: Open Source , OSI Approved
Lifecycle: Build
CycloneDX CLI
CycloneDX

CLI tool for SBOM analysis, merging, diffs, format conversions, signing, and validation. Supports CycloneDX XML/JSON/Protobuf/CSV, SPDX JSON, and more.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build , Discovery
CycloneDX Core for Java
OWASP Foundation (CycloneDX Project)

Java library for creating, parsing, and validating CycloneDX SBOMs.


Supported Languages: Java
Availability: Open Source
Lifecycle: Build
CycloneDX for .NET
CycloneDX

Generates CycloneDX Software Bill of Materials (SBOM) from .NET projects.


Supported Languages: .NET
Availability: Open Source
Lifecycle: Build
CycloneDX for Bower
Hans Thorhauge Dam

Creates CycloneDX Software Bill of Materials (SBOM) from JavaScript projects that manage dependencies with Bower.


Supported Languages: Javascript
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Cocoapods
CycloneDX

Creates CycloneDX SBOMs for Objective-C and Swift projects that use CocoaPods.


Supported Languages: Swift
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
CycloneDX for Conan1
CycloneDX

Creates CycloneDX Software Bill of Materials (SBOM) for C/C++ projects using Conan1 (note: considered deprecated)


Supported Languages: C/C++
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build
CycloneDX for Conan2
Conan-IO

Creates CycloneDX Software Bill of Materials (SBOM) for C/C++ projects using Conan2


Supported Languages: C/C++
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build
CycloneDX for Erlang/Elixir (Mix)
Bram Verburg

Mix task that generates CycloneDX SBOMs for Erlang/Elixir projects, exporting XML or JSON and supporting multiple CycloneDX schema versions.


Supported Languages: Erlang Elixir
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Erlang/Elixir (Rebar3)
Bram Verburg

Rebar3 plug-in that generates CycloneDX SBOMs for Erlang/Elixir projects, exporting XML or JSON and supporting CycloneDX v1.4.


Supported Languages: Erlang Elixir
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Go
Ozon

Command-line utility and Go library that generates CycloneDX SBOMs from Go module projects for supply-chain transparency.


Supported Languages: Go
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Go modules
OWASP Foundation – CycloneDX Project

Command-line utility and Go library that generates CycloneDX SBOMs from Go modules, binaries and applications.


Supported Languages: Go
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Gradle
CycloneDX

Gradle plugin that generates CycloneDX SBOMs (XML or JSON) for all dependencies in Java-based builds.


Supported Languages: Java
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Maven
OWASP Foundation / CycloneDX Project

Apache Maven plugin that automatically generates CycloneDX SBOMs (JSON or XML) for Java projects and can attach vulnerability disclosure information.


Supported Languages: Java
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Node.js
OWASP Foundation (CycloneDX Project)

This is a so-called meta-package, it does not ship any own functionality, but it is a collection of optional dependencies with one purpose in common: generate CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects.


Supported Languages: Javascript , Node.js
Availability: Open Source , OSI Approved
Lifecycle: N/A
CycloneDX for NPM
CycloneDX

Create CycloneDX Software Bill of Materials (SBOM) from npm projects.


Supported Languages: Javascript , Node.js
Availability: Open Source , OSI Approved
Lifecycle: Design , Pre Build , Build , Post Build , Operations
CycloneDX for PHP Composer
CycloneDX

Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects.


Supported Languages: PHP
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build , Operations
CycloneDX for Python
CycloneDX

Generates CycloneDX SBOMs from Python (virtual) environments, requirement files, and manifests (Poetry, PipEnv, etc)


Supported Languages: Python
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build , Operations
CycloneDX for Ruby Gems
OWASP Foundation

Command-line utility and Ruby library that generates CycloneDX SBOMs for Ruby projects by analysing Gem dependencies.


Supported Languages: Ruby
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Rust Cargo
CycloneDX Project (OWASP)

Cargo sub-command and CLI library that generates CycloneDX SBOMs for Rust projects, aggregating all crate dependencies and outputting JSON or XML.


Supported Languages: Rust
Availability: Open Source
Lifecycle: Build , Post Build , Discovery
CycloneDX for SBT (Scala)
Fabrizio Di Giuseppe

SBT plugin that generates CycloneDX SBOMs (JSON or XML) for Scala/Java builds, supporting schema v1.6 and integrating smoothly with Dependency-Track.


Supported Languages: Java , Scala
Availability: Open Source
Lifecycle: Build , Post Build
CycloneDX for Webpack
OWASP Foundation

Webpack plugin that generates CycloneDX Software Bill of Materials (SBOM) for JavaScript/TypeScript bundles during the build process.


Supported Languages: Javascript , Node.js
Availability: Open Source , OSI Approved
Lifecycle: Build
CycloneDX for Yarn
CycloneDX

Create CycloneDX Software Bill of Materials (SBOM) from yarn projects.


Supported Languages: Node.js , Javascript
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build , Operations
CycloneDX GoMod Generate SBOM
CycloneDX

GitHub action which generates CycloneDX SBOMs from Go modules, providing integration into CI/CD workflows for Go projects.


Supported Languages: Go
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
CycloneDX JavaScript Library
CycloneDX

Core functionality of CycloneDX for JavaScript (Node.js or Web Browser) written in TypeScript.


Supported Languages: Javascript , Node.js
Availability: Open Source , OSI Approved
Lifecycle: N/A
CycloneDX Libraries for .NET
CycloneDX

.NET libraries to consume and produce CycloneDX Software Bill of Materials (SBOM).


Supported Languages: .NET
Availability: Open Source
Lifecycle: Design , Build , Post Build
CycloneDX library for Go
CycloneDX

Go library that can parse, create and serialize CycloneDX Software Bill of Materials (SBOM) in JSON or XML.


Supported Languages: Go
Availability: Open Source
Lifecycle: Design , Build , Post Build
CycloneDX Node.js Generate SBOM
CycloneDX

GitHub Action to create a CycloneDX Software Bill-of-Materials (SBOM) for Node.js projects containing an aggregate of all project dependencies. (note: considered deprecated)


Supported Languages: Node.js , Javascript
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build
CycloneDX Perl Library
Giuseppe Di Terlizzi

Perl library for generating CycloneDX SBOMs.


Supported Languages: Perl
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
CycloneDX PHP Composer Generate SBOM
CycloneDX

GitHub Action to create a CycloneDX Software Bill-of-Materials (SBOM) for PHP Composer projects (note: considered deprecated)


Supported Languages: PHP
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build
CycloneDX PHP Library
CycloneDX

PHP library that supplies data-models, serializers, validators and utilities for creating, parsing and validating CycloneDX BOM documents in JSON and XML formats.


Supported Languages: PHP
Availability: Open Source , OSI Approved
Lifecycle: N/A
CycloneDX Python Generate SBOM
CycloneDX

GitHub Action to create a CycloneDX Software Bill-of-Materials (SBOM) for Python projects from requirements files (note: considered deprecated)


Supported Languages: Python
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build
CycloneDX Python Library
CycloneDX

This Python package provides data models, validators and more, to help you create/render/read CycloneDX documents.


Supported Languages: Python
Availability: Open Source , OSI Approved
Lifecycle: N/A
CycloneDX Rust
Mark Dodgson

Simple Rust library to encode and decode CycloneDX BOMs.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery
CycloneDX Web Tool
CycloneDX

Web-based tool for validating, viewing, and converting CycloneDX SBOMs. Supports XML/JSON, and conversion between CycloneDX and SPDX formats.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery
cyclonedx_deps_to_mermaid.xsl
Jan Kowalleck

Extensible Stylesheet Language Transformations (XSLT) to translate CycloneDX dependency graph to mermaid chart.


Supported Languages: Javascript , Java , PHP
Availability: Open Source
Lifecycle: Build , Post Build , Operations
CycloneDX-Buildroot
CycloneDX

Python application that generates CycloneDX Software Bill of Materials (SBOM) for Buildroot-generated projects and other projects with CSV manifest files


Supported Languages: C/C++
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
cyclonedx-editor-validator
Festo SE & Co. KG

Command-line utility to create, merge, edit and validate CycloneDX SBOMs and VEX files for automated CI/CD workflows.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust , Swift
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
cyclonedx-enrich
fnxpt

Enrich CycloneDX SBOM files by applying enrichers to improve data quality, including licenses, hashes, properties, and references.


Supported Languages: Java , Javascript , Python , Ruby
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
cyclonedx-merge
fnxpt

Tool to merge CycloneDX files (JSON/XML) with support for normal, flat, and smart merge modes.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
cyclonedx-npm-pipe
ShiftLeftCyber

Bitbucket Pipe that packages cdxgen in a Docker image to generate CycloneDX v1.6 SBOMs for Node.js/npm projects in CI pipelines.


Supported Languages: Node.js
Availability: Open Source , OSI Approved
Lifecycle: Build
DaggerBoard
NewYork-Presbyterian Hospital

Vulnerability-scanning application that ingests CycloneDX or SPDX SBOM files, analyses listed dependencies for known CVEs, and presents results through a web dashboard.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
Debricked
OpenText

Debricked lets teams automatically find, fix and prevent open-source vulnerabilities, avoid non-compliant licences and pick healthier dependencies, with CycloneDX SBOM import/export, CLI and SaaS dashboards.


Supported Languages: Java , Javascript , .NET , PHP , Python , Ruby
Availability: Freemium
Lifecycle: Design , Pre Build , Build , Post Build , Operations
Defect Dojo
OWASP

Open source vulnerability management and automation platform that can import CycloneDX SBOMs and over 190 security tool reports for centralized vulnerability tracking and analysis.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build , Operations , Discovery
Dependency-Track
OWASP

An intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain by leveraging SBOMs


Supported Languages: Java , Javascript , Python , Ruby , PHP , Rust , C/C++ , .NET , Perl , Erlang Elixir
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build , Post Build
Dependency-Track Jenkins Plugin
OWASP

Jenkins plugin that publishes CycloneDX Software Bill-of-Materials (SBOM) to the Dependency-Track platform for vulnerability analysis and policy evaluation


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
Dependency-Track Maven Plugin
Paul McKeown

Maven plugin that integrates with a Dependency-Track server to submit SBOMs and optionally fail execution when vulnerable dependencies are found


Supported Languages: Java
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
Distro2SBOM
Anthony Harrison

A command line tool which creates CycloneDX and SPDX SBOMs for an installed application or distribution (Debian, RPM, Windows and FreeBSD systems supported).


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
docker-sbom-cli-plugin
Docker

Docker CLI plugin that generates Software Bills of Materials (SBOMs) for container images using Syft as the underlying scanner, with CycloneDX output support.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery
dtrack-audit
OZON

Command-line client for OWASP Dependency-Track that publishes SBOMs and displays vulnerability information from the command line, designed for CI/CD integration


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build
DtrackAuditor
Thinksabin

Python CLI tool to upload CycloneDX SBOMs to Dependency-Track, analyze vulnerabilities, enforce policy, and fail CI builds based on thresholds.


Supported Languages: Python
Availability: Open Source
Lifecycle: Post Build
Eclipse SW360 Antenna
Eclipse Foundation

Archived tool that scanned project artifacts, downloaded sources for dependencies, validated licenses, and generated license compliance documentation


Supported Languages: Java
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
EMBA
EMBA Project

EMBA is an open-source firmware security analyzer that extracts firmware, performs static and dynamic analysis, builds CycloneDX SBOMs with VEX data, and generates detailed vulnerability reports.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery
Endor Labs
Endor Labs

Cloud-native platform that auto-creates CycloneDX SBOMs, generates VEX, and analyzes reachability so teams can securely select, integrate and maintain open-source software at scale.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby
Availability: Subscription , Commercial License
Lifecycle: Build , Post Build , Operations , Discovery
Enso
Enso Security

Application Security Posture Management (ASPM) platform that inventories software assets, tracks AppSec tools and processes, and outputs CycloneDX and SPDX SBOMs with optional VEX ingest.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Discovery , Operations
EXPLIoT IoT Security Assessment Framework
EXPLIoT

EXPLIoT is an AGPLv3 Python framework and CLI for assessing and exploiting IoT devices; it offers 140+ plug-ins and can generate CycloneDX SBOMs from firmware filesystems.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Operations
FACT
aDolus Technology Inc.

The aDolus FACT platform is an advanced aggregation, analytics, and correlation engine that generates NTIA-compliant SBOMs (including CycloneDX) and provides continuous cybersecurity risk intelligence across the software supply chain.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Operations
Flawnter
CyberTest

Flawnter is a zero-trust static, dynamic and composition analysis platform that detects code flaws, vulnerabilities and license risks, and generates CycloneDX/SPDX SBOMs during every scan.


Supported Languages: C/C++ , .NET , Java , Kotlin , Javascript , Node.js , PHP , Python , Go , Ruby , Rust , Swift
Availability: Freemium , Subscription
Lifecycle: Build , Operations
Fortify on Demand
Micro Focus

SaaS application-security testing platform offering SAST, DAST and SCA. Produces and consumes CycloneDX SBOMs to secure the software supply chain across many languages, frameworks and package managers.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Scala , Kotlin , Swift
Availability: Subscription , Commercial License
Lifecycle: Pre Build , Build , Post Build , Operations
Fortify Software Security Center
Micro Focus

Open-source CycloneDX parser plugin for Fortify SSC that imports SBOMs, correlates components with known vulnerabilities and licenses, and displays them in the SSC portal.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
Fortress Asset 2 Vendor
Fortress Information Security

Comprehensive cyber supply chain risk management platform that ingests, analyzes and securely shares SBOMs, HBOMs and other supply chain attestations via SaaS and permissioned blockchain.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Post Build , Operations , Discovery
Fortress File Integrity Assurance
Fortress Information Security

A proprietary software analysis tool that validates patches and ensures software file integrity to enhance software supply chain security in critical infrastructure environments.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Post Build , Operations
FOSSA
FOSSA

Subscription SCA platform and CLI that generate, import, analyse, and distribute CycloneDX or SPDX SBOMs for licence and vulnerability risk management across CI/CD pipelines.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Pre Build , Post Build , Operations
Gemnasium
GitLab

Dependency scanning analyzer that uses the GitLab Advisory Database to detect vulnerabilities in project dependencies and generates CycloneDX SBOMs.


Supported Languages: Ruby , Python , Javascript , Node.js , Java , Go , PHP
Availability: Commercial License , Freemium
Lifecycle: Build , Post Build
Generate SBoM for Elixir project
Red Shirts

GitHub Action to generate CycloneDX Software Bill-of-Materials (SBOM) for Erlang/Elixir Mix projects


Supported Languages: Erlang Elixir
Availability: Open Source
Lifecycle: Build , Post Build
gh-sbom
GitHub

CLI extension for the gh tool that generates CycloneDX or SPDX JSON SBOMs for any GitHub repository using Dependency Graph data.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
Go Sonatypes
Sonatype

Common utility packages for working with OSS Index, Nexus IQ Server, CycloneDX SBOMs or getting a user-agent


Supported Languages: Go
Availability: Open Source
Lifecycle: Build
gobom
Mattermost

An extensible CycloneDX BOM generator and Dependency-Track API client written in Go; supports Go, npm, CocoaPods and Gradle projects and uploads SBOMs for analysis.


Supported Languages: Go , Javascript , Java , Swift
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
Grype
Anchore

A vulnerability scanner for container images and filesystems. Works with Syft SBOMs and supports CycloneDX, SPDX, and OpenVEX.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Open Source , OSI Approved
Lifecycle: Discovery , Operations
Heimdall
MedCrypt

Automatically extract or manually upload your Software Bill of Materials (SBOM), and Heimdall will, on a continual basis, identify known vulnerabilities affecting your software components


Supported Languages: N/A
Availability: Commercial License , Subscription
Lifecycle: Post Build , Operations , Discovery
Ion Channel Platform
Ion Channel

Risk management platform that enables analysis, exchange and continuous monitoring of Software Bills of Materials (SBOMs) to actively manage third party risk and compliance


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Operations
ittosai
DevOps KungFu Masters

ittosai is a CycloneDX SBOM vulnerability analyzer that analyzes SBOMs every time a developer commits code to a repository.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Post Build , Build
Jake
Sonatype

An OSS Index integration to check your Conda environments for vulnerable Open Source packages


Supported Languages: Python
Availability: Open Source
Lifecycle: Build
jbom
Eclipse Foundation (originally Contrast Security)

jbom generates runtime and static CycloneDX SBOMs for local or remote Java applications and archives.


Supported Languages: Java
Availability: Open Source
Lifecycle: Operations , Discovery
JDisc Discovery
JDisc

Network discovery and IT inventory tool that can discover CycloneDX SBOMs on enterprise assets and ingest component inventory into the platform.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Discovery , Operations
Jetstack Secure
Jetstack

Manages machine identities across Cloud Native Kubernetes and OpenShift environments, providing a detailed view of enterprise security posture for TLS certificates and PKI.


Supported Languages: N/A
Availability: Open Source , Commercial License
Lifecycle: Operations , Discovery
JupiterOne
JupiterOne

Easily identify, map, analyze, and secure cyber assets and attack surface. Gain full visibility into complex cloud environments to uncover threats, close compliance gaps, and prioritize risk.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Discovery , Operations
kbom - Kubernetes Bill of Materials powered by KSOC
KSOC

kbom is an open-source CLI tool from KSOC, written in Go, that generates detailed CycloneDX SBOMs for Kubernetes clusters, including nodes, control plane, OS, and cloud infrastructure details.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Operations , Discovery
Keysight IoT Security Assessment
Keysight

Automated firmware analysis platform that generates SBOMs and identifies vulnerabilities, misconfigurations, hardcoded credentials, weak cryptography, and potential zero-day vulnerabilities in IoT devices.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Discovery , Operations
KICS
Checkmarx

KICS scans Infrastructure-as-Code to detect security vulnerabilities, compliance issues and misconfigurations, exporting results as CycloneDX SBOM and VDR reports.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Pre Build , Build , Post Build
Ko
Ko Build

Simple, fast container image builder for Go applications that generates CycloneDX SBOMs by default, supports multi-platform builds, and integrates seamlessly with Kubernetes.


Supported Languages: Go
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
Kondukto
Kondukto

Application Security Orchestration and Correlation platform that generates and consumes CycloneDX or SPDX SBOMs, correlates vulnerability scanner findings, and automates remediation workflows across CI/CD pipelines.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Pre Build , Post Build , Operations
KubeClarity
Cisco

Open-source platform (CLI, UI & Helm chart) that generates SBOMs, converts them between CycloneDX/SPDX formats, and scans container images, directories and running Kubernetes clusters for vulnerabilities, licences and CIS Docker benchmark findings.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build , Operations , Discovery
Kyverno
Kyverno Project (CNCF Incubating)

Kyverno is an open-source Kubernetes policy engine that validates, mutates and generates configurations, and can evaluate CycloneDX SBOM attestations to enforce supply-chain policies.


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build , Operations
Lagoon Insights Handler
Lagoon

Component that processes CycloneDX SBOMs and container image metadata for Lagoon environments, with vulnerability analysis via Trivy integration and customizable data filtering.


Supported Languages: Go
Availability: Open Source
Lifecycle: Post Build , Operations
Lib4sbom
Anthony Harrison

Python library that parses, converts and generates SBOMs in CycloneDX and SPDX formats, allowing JSON, Tag, YAML and XML serialization and programmatic manipulation of packages, files and dependencies.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Build
License Scanner
CycloneDX

license-scanner is an Apache-2.0 Go library and CLI that detects SPDX-style licenses and legal terms in source files and outputs CycloneDX v1.4 SBOMs with detailed license data.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Build
LicenseComplianceTool
medavis GmbH

Creates license manifests from CycloneDX SBOMs. Provides a Jenkins build step and CLI to list third-party components, their licenses, and download license texts to aid open-source compliance.


Supported Languages: Java , Node.js , Javascript
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
macaron
Oracle

Macaron is a supply chain security analysis tool and policy engine that checks conformance to frameworks such as SLSA, integrating CycloneDX SBOM generators or consuming existing SBOMs for automated analysis of build integrity and dependencies.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Discovery
Manifest
Manifest

Manifest is a subscription SBOM management platform that auto-generates, aggregates, enriches, analyzes, and securely shares CycloneDX or SPDX SBOMs via web app and GitHub Action integration.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Post Build , Operations
mdbom
Robert Hansel

A simple command line tool to transform CycloneDX SBoMs to markdown.


Supported Languages: Python , Javascript , Go
Availability: Open Source
Lifecycle: Post Build
MedScan
MedSec

Consumes SBOMs to help hospitals manage medical device assets, providing vulnerability and resource analysis for compliance and risk management.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Operations , Discovery
Mend SCA
Mend (Whitesource)

Mend SCA provides software composition analysis that scans direct and transitive open-source dependencies, enforces security and license policies, and exports CycloneDX or SPDX SBOMs with optional VEX data.


Supported Languages: Java , Javascript , Python , Go , .NET , Node.js , PHP , Ruby , C/C++
Availability: Subscription
Lifecycle: Build , Operations
Meta Package Manager
Kevin Deldycke

Export a SBOM of all packages installed on a Linux, macOS or Windows system.


Supported Languages: .NET , Java , Javascript , Python
Availability: OSI Approved
Lifecycle: Build , Post Build , Operations
meta-dependencytrack
BG Networks

meta-dependencytrack is a Yocto meta-layer which produces a CycloneDX Software Bill of Materials (aka SBOM) from your root filesystem and then uploads it to a Dependency-Track server against the project of your choice


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
Meterian BOSS scanner
Meterian

Software composition analysis that inventories codebases and produces CycloneDX SBOMs while detecting security and licence risks across 12+ ecosystems.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift
Availability: Freemium , Subscription
Lifecycle: Pre Build , Build , Post Build , Operations
MLBOMdoc
Anthony Harrison

A command line tool which produces a human-readable representation of a CycloneDX ML Bill of Materials (MLBOM). Output formats include PDF and Markdown.


Supported Languages: Python
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
Nancy
Sonatype

A tool to check for vulnerabilities in your Golang dependencies, powered by Sonatype OSS Index


Supported Languages: Go
Availability: Open Source
Lifecycle: Build
Neo4Cyclone
Javier Dominguez

Neo4Cyclone is a tool that allows you to visualise your SBOMs using Neo4J.


Supported Languages: Python
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
NetRise Turbine
NetRise

Firmware analysis platform that creates SBOMs by analyzing binary artifacts, configuration files, credentials and cryptographic artifacts for holistic risk identification.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Discovery , Operations
Nexus IQ
Sonatype

Software Composition Analysis (SCA) platform that can consume, analyze, and produce CycloneDX SBOMs


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Swift
Availability: Commercial License
Lifecycle: Build , Operations
Nexus Lifecycle Jenkins Plugin
Sonatype

Publishes CycloneDX SBOMs to Nexus IQ for per-build analysis, result visualization, and policy evaluation


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift
Availability: Open Source
Lifecycle: Build
nim_lk
Emery Hemingway

Create and update SBOMs for the Nim programing language. Includes a translation module for the Nimble package manager as well as a Nix expression for building packages from SBOMs.


Supported Languages: Nim
Availability: Open Source
Lifecycle: Build , Post Build
Noma
Noma Security

AI Application Security Platform for the entire AI lifecycle, focusing on AI asset discovery, ML-BOM, and AI supply chain risk management.


Supported Languages: Javascript , Python , Java , C/C++ , .NET , Rust , Go
Availability: Commercial License
Lifecycle: Design , Build , Post Build , Operations
NowSecure Platform
NowSecure

Mobile application security testing solution that automates static, dynamic and interactive testing, with SBOM capabilities through GitHub integrations


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Build , Post Build , Operations
Ochrona CLI
Ochrona

A command line tool for detecting vulnerabilities in Python dependencies and doing safe package installs. Outputs CycloneDX SBOMs and supports policy enforcement.


Supported Languages: Python
Availability: Open Source
Lifecycle: Pre Build , Build , Post Build
Oligo Runtime SBOM
Oligo

Oligo Security delivers instant insights into actively executed libraries, assessing open source risks and confirming exploitability. It enables CycloneDX SBOM creation and auto-generates VEX.


Supported Languages: .NET , Java , Javascript , Python
Availability: Commercial License
Lifecycle: Operations , Discovery
ONEKEY firmware analysis platform
ONEKEY

Cloud-based platform that automatically extracts firmware images, enumerates components, and produces CycloneDX SBOM and vulnerability reports.


Supported Languages: N/A
Availability: Subscription , Commercial License
Lifecycle: Post Build , Discovery
OpenRewrite
OpenRewrite Project

Open-source automated refactoring ecosystem for code transformation, security remediation, and dependency management through reusable recipes and build tool plugins.


Supported Languages: Java , Kotlin , Groovy , Javascript
Availability: Open Source , OSI Approved
Lifecycle: Build , Discovery
OSS Inventory
Thiago Pinto

A web application for importing, storing, and visualizing CycloneDX SBOMs, allowing organizations to track software components across projects.


Supported Languages: N/A
Availability: Open Source
Lifecycle: N/A
OSS Review Toolkit (ORT)
OSS Review Toolkit

A comprehensive suite of tools to automate software compliance checks, analyze dependencies / vulnerabilities, and generate reports.


Supported Languages: C/C++ , .NET , Go , Java , Javascript , Kotlin , Node.js , PHP , Python , Ruby , Rust , Scala , Swift
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
oss_inventory
Thiago Pinto

A tool to import CycloneDX BOMs and visualize open source software statistics for dependency analysis and reporting


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build
OSV
Google

Open source vulnerability database and scanner that accepts CycloneDX SBOMs as input and identifies known vulnerabilities in components across multiple ecosystems.


Supported Languages: Go , Java , Javascript , Node.js , Python , Ruby , Rust , .NET
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations , Discovery
Parlay
Snyk

Parlay is an Apache-licensed CLI written in Go that takes CycloneDX 1.4 JSON/XML or SPDX 2.3 SBOMs and enriches them with licence, vulnerability, maintainer and scorecard data from services like ecosyste.ms, Snyk and OpenSSF.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
pip-audit
Trail of Bits

Audits Python environments and dependency trees for known vulnerabilities and can emit CycloneDX SBOMs of affected components.


Supported Languages: Python
Availability: Open Source
Lifecycle: Pre Build , Build , Post Build , Operations
Prisma Cloud
Palo Alto Networks

Unified cloud-native application protection platform that scans code, pipelines, infrastructure and runtime to generate CycloneDX SBOMs, analyze vulnerabilities, licenses and misconfigurations, and secure entitlements across multi-cloud environments.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby
Availability: Subscription , Commercial License
Lifecycle: Build , Post Build , Operations , Discovery
Product Security Hub (PSH)
Product Security Hub, LLC

Cloud-based tool to import, export, view, create, edit, and transform CycloneDX SBOMs and human-readable SBOMs, as well as manage VEX data.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Build , Post Build , Operations
Project Piper
SAP

Project Piper is an open-source Jenkins shared library and CLI that automates SAP-centric CI/CD pipelines and can generate CycloneDX SBOMs for Maven, Python, Go, container, and other builds.


Supported Languages: Java , Python , Go , Javascript
Availability: Open Source , OSI Approved
Lifecycle: Build
PulseUno Plugin for Dimensions CM
Micro Focus

PulseUno enables development teams to continually build and inspect the health and quality of code using plugins such as CycloneDX. Teams can use this information for merge, deployment, and release decisions.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Build , Post Build
RapidFort
RapidFort

Container-optimization platform that scans, profiles and hardens images, generates SBOMs, converts to CycloneDX/SPDX, and exports VEX to prioritize exploitable CVEs.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Pre Build , Build , Post Build , Operations
ReARM
Reliza

ReARM is a system to store, organize and manage SBOMs / xBOMs with Component and Product releases.


Supported Languages: .NET , Java , Javascript , Python , Go , Node.js
Availability: Open Source , OSI Approved , Commercial License
Lifecycle: Pre Build , Build , Post Build , Operations , Decommission
Rebom
Reliza

Open source catalog for storing, managing, and distributing CycloneDX Software Bills of Materials (SBOMs) in JSON format, with features for validation, merging, and analysis.


Supported Languages: Javascript
Availability: Open Source , OSI Approved
Lifecycle: Operations , Post Build
Reliza Hub
Reliza

Publishes and ingests SBOMs for metadata management, compliance, and distribution. Supports CycloneDX and SPDX standards for software supply chain transparency.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Post Build , Discovery , Operations
Retire.js
RetireJS

Scanner that detects the use of JavaScript libraries with known vulnerabilities in web and Node.js applications and can generate CycloneDX-format SBOMs.


Supported Languages: Javascript , Node.js
Availability: Open Source
Lifecycle: Pre Build , Build , Post Build , Discovery
Rezilion Dynamic SBOM
Rezilion

Continuous, runtime-aware SBOM platform that inventories every file, package and dependency across Windows and Linux hosts, containers and CI/CD pipelines, exports CycloneDX/VEX and validates vulnerability exploitability in real time.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Python , Ruby
Availability: Subscription , Commercial License
Lifecycle: Build , Post Build , Operations , Discovery
RKVST SBOM Hub
RKVST

Free SaaS repository to discover, store and permission-share CycloneDX v1.4 SBOMs with immutable provenance, VEX support and continuous assurance.


Supported Languages: Python
Availability: Freemium
Lifecycle: Post Build , Operations , Discovery
Rollup Plugin SBOM
Jan Biasi

Creates CycloneDX SBOMs for frontend Javascript apps bundled with rollup or vite.


Supported Languages: Javascript
Availability: Open Source
Lifecycle: Build , Post Build
RunSafe C/C++ Build-time SBOM Generator
RunSafe Security

Generates a C/C++ SBOM at build-time without a package manager, working across build environments and reporting on all library dependencies.


Supported Languages: C/C++
Availability: Commercial License
Lifecycle: Build , Post Build
Salus
Coinbase

Salus is a tool for coordinating the execution of security scanners. Salus can generate CycloneDX SBOMs from many language ecosystems.


Supported Languages: Ruby , Javascript , Node.js , Python , Go , Rust
Availability: Open Source
Lifecycle: Build , Post Build
SBOM Assembler
Interlynk.io

sbomasm is a command-line tool that assembles product SBOMs from component SBOMs, supporting CycloneDX and SPDX formats for streamlined management and distribution.


Supported Languages: Go
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
SBOM Benchmark
Interlynk.io

SBOM Benchmark is an Apache-licensed web application that scores CycloneDX 1.4/1.5 and SPDX SBOMs for quality and compliance, generating shareable reports via the sbomqs engine.


Supported Languages: N/A
Availability: Open Source , OSI Approved , Freemium
Lifecycle: Post Build , Operations , Discovery
SBOM CLI
Defense Unicorns

Creates CycloneDX SBOMs from Kubernetes Helm charts


Supported Languages: N/A
Availability: N/A
Lifecycle: N/A
SBOM Explorer
Interlynk.io

sbomex is a command line utility to help query and pull from Interlynk's public SBOM repository.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Discovery
SBOM Grep
Interlynk.io

Command-line utility (`sbomgr`) that performs grep-style searches across SBOMs by name, checksum, CPE, and PURL.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
SBOM Insights
Revenera

SBOM Insights is a subscription-based SaaS platform that ingests SBOMs in CycloneDX and SPDX formats, reconciles and analyzes components for vulnerabilities, license compliance and outdated parts, and generates reports and compliance artifacts.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Post Build , Operations , Discovery
SBOM Observer
Bytesafe

SBOM Observer provides a comprehensive SBOM workflow to help you manage your software supply chain. Leverage the powerful combination of the Policy Engine and Operational Model to guarantee the security and compliance of your software.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift , Erlang Elixir , Scala , Kotlin , Groovy , Fortran
Availability: Subscription , Commercial License
Lifecycle: Build , Post Build , Operations , Discovery
SBOM Quality Score
Interlynk.io

Command-line utility that evaluates the quality and compliance of CycloneDX and SPDX SBOMs across multiple categories, enabling automated policy gates in CI/CD workflows.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
SBOM Scorecard
eBay

SBOM Scorecard evaluates SBOMs for specification compliance, generation metadata, and package details, supporting CycloneDX, SPDX, and Syft formats.


Supported Languages: Go
Availability: Open Source , OSI Approved
Lifecycle: N/A
SBOM Utility (sbom-utility)
CycloneDX

Go-based CLI and API to validate, query, trim and patch CycloneDX or SPDX BOMs, report on components, licences and vulnerabilities, and handle all CycloneDX variants up to v1.6.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build , Operations
SBOM Vendor Management
SettleTop, Inc.

Manage, assess, store and monitor all your vendor’s SBOMs in one secure, centralized dashboard to improve supply chain security.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Operations , Discovery
sbom-action
Pete Wagner

GitHub Action that fetches and diffs CycloneDX SBOMs for container images, posting comments or opening pull requests when package or vulnerability changes are detected.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
SBOM-Manager
Anthony Harrison

SBOM-Manager is an open-source Python CLI that stores, queries, and scans CycloneDX 1.4/1.5 and SPDX 2.3 SBOMs via a local repository to support audit and vulnerability investigations.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
SBOM-Operator
Christian Kotzbauer

Catalogue all container images running in a Kubernetes cluster and publish Software Bill of Materials (SBOM) documents, generated with Syft, to multiple back-ends.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Operations , Discovery
sbom-rs
Paul Sastrasinh

A group of Rust projects for interacting with and producing software bill of materials (SBOMs).


Supported Languages: Rust
Availability: Open Source
Lifecycle: Build , Post Build
sbom-submission-action
TietoEVRY

GitHub Action that uploads CycloneDX SBOM files to GitHub’s dependency submission API, enabling Dependabot security analysis downstream.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
sbom-swissarmy-bitbucket-pipe
ShiftLeftCyber

A Bitbucket Pipe containing a collection of open source tools to perform additional analysis on a CycloneDX or SPDX SBOM.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift , Erlang Elixir , Scala , Kotlin , Groovy , Fortran
Availability: Open Source , OSI Approved
Lifecycle: Design , Pre Build , Build , Post Build , Operations , Discovery , Decommission
sbom-validator
ShiftLeftCyber

A lightweight Go library for validating Software Bill of Materials (SBOM) against industry-standard specifications.


Supported Languages: Go
Availability: Open Source
Lifecycle: Build , Post Build , Operations
SBOM.sh
Codenotary Inc

SBOM.sh is a free service to store, visualize and globally share CycloneDX SBOM files by simply using HTTP requests or curl.


Supported Languages: Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Open Source , Freemium
Lifecycle: Post Build , Operations
SBOM2doc
Anthony Harrison

SBOM2doc converts CycloneDX or SPDX SBOMs into human-readable reports in PDF, Markdown, HTML, Excel or console formats via a cross-platform Python CLI.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
SBOM2dot
Anthony Harrison

CLI that reads CycloneDX or SPDX SBOMs and emits a GraphViz-compatible DOT file so you can visualise component and dependency relationships.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery
SBOM4Files
Anthony Harrison

Command-line tool that scans a directory and generates CycloneDX (JSON) or SPDX SBOMs for its files.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
SBOM4Python
Anthony Harrison

CLI utility that produces CycloneDX or SPDX SBOMs for installed Python modules or requirements files, identifying dependencies and their licenses, with optional dependency graph output.


Supported Languages: Python
Availability: Open Source , OSI Approved
Lifecycle: Pre Build , Post Build
SBOM4Rust
Anthony Harrison

CLI that reads Cargo.lock and authors CycloneDX v1.6 or SPDX SBOMs for Rust projects.


Supported Languages: Rust
Availability: Open Source , OSI Approved
Lifecycle: Pre Build
SBOMAudit
Anthony Harrison

SBOMAudit is a command-line utility that audits CycloneDX or SPDX SBOMs against NTIA minimum requirements, license policies, allow/deny lists, and package age to flag outdated or non-compliant components.


Supported Languages: Go , Java , Javascript , .NET , Perl , Python , Ruby , Rust , Swift
Availability: Open Source , OSI Approved
Lifecycle: Post Build
SBOMcenter
Codenotary Inc

SBOMcenter.io is a free service to get insights into the ingredients of your software for free and without any software.


Supported Languages: Java , Python , Javascript , Go , Rust
Availability: Open Source , Freemium
Lifecycle: Build , Post Build , Operations
SBOMDiff
Anthony Harrison

SBOMDiff is an Apache-2.0 CLI that compares two SBOM files (CycloneDX 1.4 or SPDX 2.3), highlighting package additions, removals, version or license changes, and outputs text, JSON or YAML reports.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
sbomify
sbomify

sbomify is a comprehensive SBOM management platform that enables secure sharing and analysis of Software Bill of Materials. Seamlessly integrates with CI/CD pipelines.


Supported Languages: Javascript
Availability: Open Source
Lifecycle: Build , Post Build , Operations
SBOMMerge
Anthony Harrison

Command-line utility that merges two SBOM files, supporting CycloneDX and SPDX inputs and outputs in tag, JSON or YAML formats.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
SBOMTrend
Anthony Harrison

A command line tool which analyses a set of SBOMs to identify license and version changes in components.


Supported Languages: Python
Availability: Open Source , OSI Approved
Lifecycle: Post Build
sca-codeinsight-reports-cyclonedx
Flexera

Generates CycloneDX SBOM reports (XML and JSON) for projects scanned in Flexera Code Insight.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
Scancode Toolkit
nexB

Detects licenses, copyrights, package manifests & dependencies by scanning code to discover and inventory open source and third-party packages


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift
Availability: Open Source
Lifecycle: Build , Post Build , Discovery
SCANOSS
SCANOSS

Open source software identification and inventory tool that provides insights into license compliance, security vulnerabilities, and software composition analysis


Supported Languages: C/C++ , Java , Javascript , Python
Availability: Open Source
Lifecycle: Build , Post Build
SecObserve
MaibornWolff

Open-source platform that aggregates findings and CycloneDX SBOMs from many scanners, lets teams assess security and license risks, and reports results via dashboards and APIs.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust , Kotlin
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build , Operations
secure.software
ReversingLabs

secure.software (Spectra Assure) protects CI/CD workflows by scanning release artifacts for malware, vulnerabilities and policy violations, then exporting CycloneDX 1.6 SBOMs, SaaSBOMs, CBOMs and AI/ML-BOMs with optional VEX.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Python , PHP , Ruby , Rust
Availability: Subscription
Lifecycle: Build , Post Build , Operations
SecureStack
SecureStack

SecureStack analyzes your application and finds all source code, cloud stack and third-party services and builds a CycloneDX SBOM every time you deploy


Supported Languages: Go , Javascript , Python
Availability: Freemium , Subscription
Lifecycle: Post Build , Operations
Semgrep
Semgrep Inc

Semgrep is an application security platform where developers can scan for vulnerabilities in code (SAST), in OSS dependencies (SCA), and secrets. Semgrep creates CycloneDX SBOMs that enrich vulnerabilities with reachability analysis.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust , Scala , Swift , Kotlin , Groovy , Fortran
Availability: Open Source , Freemium , Subscription
Lifecycle: Build , Post Build , Operations
ShiftLeft Scan
ShiftLeft

A free open-source security tool for modern DevOps teams that performs static analysis-based security testing across multiple languages and frameworks


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Open Source
Lifecycle: Pre Build , Build , Post Build
SnykVulnCheck
Andrii Grytsenko

Command-line tool that analyzes CycloneDX SBOMs and evaluates components for known vulnerabilities by querying the public Snyk Vulnerability Database API.


Supported Languages: Python
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery
Software Assurance Guardian Point Man
Reliable Energy Analytics LLC

A patented tool that performs comprehensive software supply chain risk assessments using a 7-step process to detect vulnerabilities and calculate trustworthiness scores for software.


Supported Languages: N/A
Availability: Commercial License
Lifecycle: Pre Build , Build , Post Build , Discovery
Sonar Cryptography Plugin
IBM

A SonarQube Plugin that detects cryptographic assets in source code and generates CBOM.


Supported Languages: Java , Python
Availability: Open Source
Lifecycle: Build , Post Build
SonarQube
SonarSource

SonarQube allows developers and development teams to write clean code and remediate existing code organically, so they can focus on the work they love and maximize the value they generate for businesses.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Swift , Scala , Kotlin
Availability: Open Source , Freemium , Commercial License , OSI Approved
Lifecycle: Build , Post Build , Operations
Sonatype Lift
Sonatype

Cloud-native, collaborative code analysis platform that analyzes pull requests to find and fix security, performance, reliability, and style issues while generating CycloneDX SBOMs.


Supported Languages: Java , Javascript , Python , Go , PHP , Ruby
Availability: Commercial License , Freemium
Lifecycle: Pre Build , Build
SOOS
SOOS

Automate your software inventory. SOOS creates, ingests, and manages your Software Bill of Materials and uses patented SCA and the largest open-source SBOM database to find hidden vulnerabilities, license issues, and dependencies sooner.


Supported Languages: Javascript , .NET , Java , Python , Ruby , PHP
Availability: Subscription , Commercial License
Lifecycle: Build , Post Build , Operations
Spack
Spack

HPC package manager for Linux and macOS; the spack-sbom plug-in exports CycloneDX SBOMs for any concretized spec.


Supported Languages: C/C++ , Fortran , Go , Java , Javascript , Python , Rust , Swift
Availability: Open Source
Lifecycle: Post Build , Operations
spdxcyclone
SPDX

Java utility that converts Software Bill of Materials (SBOM) documents from CycloneDX format to SPDX format, supporting multiple serialization options for both standards.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery
SRC:CLR SBOM Generator
Veracode

Generates a Software Bill of Materials in CycloneDX JSON Format from Veracode SCA Agent results


Supported Languages: N/A
Availability: Open Source
Lifecycle: Post Build
StackAware
StackAware

StackAware is a SaaS platform for managing CycloneDX 1.4/1.5 and SPDX SBOMs, enriching them with VEX data, and securely distributing both SBOMs and SaaSBOMs for supply-chain risk analysis.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Post Build , Operations , Discovery
SUM Platform
Security Pattern

SBOM management and vulnerability monitoring platform for IoT and embedded systems. Show compliance to regulations and standards and manage risk across the entire product lifecycle.


Supported Languages: C/C++ , Java , Javascript , .NET , Python
Availability: Commercial License
Lifecycle: Design , Build , Operations
Sunshine
CycloneDX

Open-source SBOM visualization tool. Converts CycloneDX JSON into interactive charts and tables for components, dependencies, vulnerabilities, and licenses.


Supported Languages: Python
Availability: Open Source
Lifecycle: Build , Post Build , Operations , Discovery
Surfactant
LLNL

A modular framework for extracting file information and relationships for filesystems, with an SBOM as the primary output.


Supported Languages: C/C++ , Java , Javascript , .NET , Python
Availability: Open Source
Lifecycle: Build , Post Build
swift-package-sbom-generator
Mattt

A software bill of materials (SBOM) generator for Swift packages


Supported Languages: Swift
Availability: Open Source
Lifecycle: Build , Post Build
SwiftBOM
CERT Coordination Center (CERT/CC)

Generates SBOMs for demo and PoC purposes. Supports output in CycloneDX, SPDX, and SWID formats. Visualizes SBOMs as tree graphs.


Supported Languages: Javascript
Availability: Open Source
Lifecycle: Build , Post Build , Discovery
Syft
Anchore

CLI tool and library for generating a Software Bill of Materials from container images and filesystems.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Open Source
Lifecycle: Build , Post Build , Discovery
Tally
Jetstack

Command-line tool that adds OpenSSF Scorecard security posture scores to packages listed in CycloneDX SBOMs.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build
Technolinator
MediaMarktSaturn Technology

GitHub App that generates CycloneDX SBOMs with cdxgen, scans them for vulnerabilities using grype, and uploads results to Dependency-Track.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Pre Build
Tern
Tern

Software composition analysis tool that generates a Software Bill of Materials for container images and Dockerfiles


Supported Languages: N/A
Availability: Open Source
Lifecycle: Build , Post Build , Discovery
ThreatMapper
Deepfence

Deepfence ThreatMapper hunts for vulnerabilities in production platforms, ranks vulnerabilities based on their risk-of-exploit using attack path enumeration, and generates CycloneDX SBOMs.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Operations , Discovery
Threatrix
Threatrix

Threatrix CodeCertify platform provides a solution for producing a comprehensive and accurate, singular, CycloneDX bill of materials from multiple sources.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , Perl , PHP , Python , Ruby , Rust , Swift , Erlang Elixir , Scala , Kotlin , Groovy , Fortran , Nim
Availability: Commercial License
Lifecycle: Build , Post Build , Operations
Tidelift
Tidelift

Tidelift provides a managed open-source subscription that delivers commercial support, maintenance, security and license assurances for the open-source dependencies used to build applications, backed directly by project maintainers.


Supported Languages: Java , Javascript , Python , Swift , Go , Rust , .NET , Ruby , Node.js
Availability: Subscription
Lifecycle: Build
Trivy
Aqua Security

Comprehensive security scanner for containers, filesystems, Git repositories, VMs and Kubernetes that detects vulnerabilities, misconfigurations, secrets and generates CycloneDX SBOMs.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Discovery , Operations
TrustSource
TrustSource

SaaS platform for implementing and maintaining open source compliance that imports CycloneDX SBOMs, analyzes them for licenses and vulnerabilities, and integrates with various development workflows.


Supported Languages: C/C++ , Java , Javascript , .NET , Node.js , Python , Ruby
Availability: Commercial License
Lifecycle: Build , Post Build , Operations , Discovery
ts-scan
TrustSource

Multi ecosystem SCA cli tool supporting SBOM generation, decoration and analysis for licenses, vulnerabilities, known code snippets and malware.


Supported Languages: Java , Javascript , Python , C/C++ , Go , .NET
Availability: Open Source
Lifecycle: Build , Post Build , Operations
Valaa Stack
Valaa Technologies

SBoMDoc is a VDoc extension which uses CycloneDX namespaces and can emit BOM documents in various formats


Supported Languages: Javascript
Availability: Open Source
Lifecycle: Build
Valint
Scribe Security

CLI and CI/CD tool for generating CycloneDX SBOMs, signing and verifying supply-chain evidence, enforcing policy, and tracking vulnerabilities across containers, source repositories, and pipelines.


Supported Languages: N/A
Availability: Open Source , OSI Approved , Subscription
Lifecycle: Pre Build , Build , Post Build , Operations
Value Stream Management (VSM)
LeanIX

SaaS catalog that ingests CycloneDX SBOMs via REST API, indexes them by team and product, and surfaces vulnerabilities, licenses and component age to secure the software supply chain.


Supported Languages: N/A
Availability: Subscription , Commercial License
Lifecycle: Post Build , Operations
Veracode
Veracode

API to output SBOM in CycloneDX (JSON) format based on Veracode's software composition analysis (SCA) scan.


Supported Languages: Java , Javascript , .NET , Python , Ruby , Go , PHP
Availability: Subscription
Lifecycle: Build , Post Build , Operations
Vexy
Paul Horton

Generate VEX (Vulnerability Exploitability Exchange) CycloneDX documents.


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Post Build , Operations
Vigiles
Timesys

Vulnerability monitoring and remediation suite that imports, generates, converts, and analyses CycloneDX or SPDX SBOMs with curated CVE feeds and build-system integrations for Yocto, Buildroot, OpenWrt, and more.


Supported Languages: N/A
Availability: Subscription
Lifecycle: Pre Build , Post Build , Operations
vsm-sbom-booster
LeanIX

CLI and Docker-based tool that scans Git providers, runs ORT, generates CycloneDX SBOMs centrally, and uploads them to LeanIX VSM to speed onboarding.


Supported Languages: C/C++ , Go , Java , Javascript , .NET , Node.js , PHP , Python , Ruby , Rust , Kotlin , Scala , Swift
Availability: Open Source , OSI Approved
Lifecycle: Build , Post Build
Vulnerabilities.io
Vulnerabilities Input Output Limited

Generates CycloneDX Software Bill of Materials (SBOM) and visualizations for an organization's codebase through integrations with source control systems. Enables organizations to manage overall supply chain risk.


Supported Languages: Java , .NET , PHP , Python , Javascript , Rust , Erlang Elixir
Availability: Commercial License
Lifecycle: N/A
Vuls
Future Corp

Agent-less vulnerability scanner for Linux, FreeBSD, containers, WordPress, programming language libraries and network devices which outputs CycloneDX Vulnerability Disclosure Reports (VDR).


Supported Languages: N/A
Availability: Open Source , OSI Approved
Lifecycle: Operations , Discovery
WpBom
Sepbit

WordPress plugin that generates CycloneDX SBOMs for installed plugins and themes, and can automatically submit them to OWASP Dependency-Track for vulnerability analysis.


Supported Languages: PHP
Availability: Open Source
Lifecycle: Post Build , Operations
Xray
JFrog

JFrog Xray is a software-composition-analysis platform that finds vulnerabilities, license issues and policy violations in open-source and third-party components, and can export CycloneDX SBOMs with optional VEX data.


Supported Languages: Go , Java , Javascript , Python , C/C++ , PHP
Availability: Freemium , Subscription
Lifecycle: Pre Build , Build , Post Build , Operations
Xygeni Software Supply-Chain Security
Xygeni

Supply-chain security platform and CLI that generates CycloneDX SBOMs, analyses vulnerabilities and misconfigurations, enforces policy in CI/CD, and integrates with DevOps tools to secure releases.


Supported Languages: Java , Javascript , Python , Go , .NET
Availability: Subscription
Lifecycle: Pre Build , Build , Post Build , Operations
yasca (Yet Another SCA tool)
Javi

Yasca (Yet Another SCA tool) is an open-source Python utility and GitHub Action that scans Maven projects against GitHub Security Advisories, detects vulnerable or outdated dependencies, and exports CycloneDX SBOMs.


Supported Languages: Java
Availability: Open Source , OSI Approved
Lifecycle: Build