scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
-
Updated
Aug 23, 2026 - JavaScript
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.
A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
SBOM, provenance, dependency graph, and vulnerability tools for Nix.
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.
Utility that provides an API platform for validating, querying and managing BOM data
Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.
creates CycloneDX Software-Bill-of-Materials (SBOM) from Node.js-based projects
A toolset for dealing with Cryptography Bill of Materials (CBOM)
Deptective automatically determines the native dependencies required to run any arbitrary program or command.
ReARM - Release Governance Platform
Validate SPDX 2 and 3 SBOM against NTIA, CISA, and other minimum element requirements.
Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects
This repository contains a SonarQube Plugin that detects cryptographic assets in source code and generates CBOM.
A tool to automatically detect copy+pasted and vendored code between repositories
To associate your repository with the sbom-tool topic, visit your repo's landing page and select "manage topics."