Supply chain toolsLocal review / optional AI
Supply chain / FREE TOOL
SBOM explorer
Make your software inventory readable. Inspect components, versions, licenses, package identifiers, and missing metadata.
02 Your results
A closer look starts here.
Add your input and run the check. We will show the observations and explain what needs review.
A QUICK WALKTHROUGH
How to use it
- 01Export a JSON SBOM from your build tooling.
- 02Inspect the component inventory and metadata gaps.
- 03Use the inventory to guide deeper dependency review.
What this check can tell you
Supports CycloneDX 1.2 through 1.7 and SPDX 2.0 through 2.3 JSON inventories. Missing metadata indicates an inventory gap, not a vulnerability. This is not a license-compliance or CVE assessment.
The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.
CycloneDX specification