Skip to main content
Supply chain tools

Supply chain / FREE TOOL

SBOM explorer

Make your software inventory readable. Inspect components, versions, licenses, package identifiers, and missing metadata.

Local review / optional AI

01 Your input

Local processing only. Maximum file size: 2 MB.

02 Your results

A closer look starts here.

Add your input and run the check. We will show the observations and explain what needs review.

 

A QUICK WALKTHROUGH

How to use it

  1. 01Export a JSON SBOM from your build tooling.
  2. 02Inspect the component inventory and metadata gaps.
  3. 03Use the inventory to guide deeper dependency review.

What this check can tell you

Supports CycloneDX 1.2 through 1.7 and SPDX 2.0 through 2.3 JSON inventories. Missing metadata indicates an inventory gap, not a vulnerability. This is not a license-compliance or CVE assessment.

The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.

CycloneDX specification