Supply chain / FREE TOOL
SBOM comparison
Compare software inventories across builds. Find added or removed components and changes to license or digest metadata.
02 Your results
A closer look starts here.
Add your input and run the check. We will show the observations and explain what needs review.
A QUICK WALKTHROUGH
How to use it
- 01Add previous and proposed JSON SBOMs.
- 02Review added, removed, ambiguous and metadata-changed identities.
- 03Confirm changes against the build artifacts and their authoritative source.
What this check can tell you
Matches exact package URLs, or exact name/version when no URL exists. Upgrades appear as removals plus additions; duplicate identities are flagged rather than paired. Compares declared metadata, not dependency edges, artifact bytes, signatures or CVEs. Supports CycloneDX 1.2 through 1.7 and SPDX 2.0 through 2.3, up to 10,000 components per file.
The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.
CycloneDX component relationships and identity