Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Free SBOM Analyzer

Drop an SBOM below and see what is in it: quality issues, known vulnerabilities, components and licenses. Free, no signup.

Drop your SBOM here

or

CycloneDX or SPDX · JSON or XML · up to 10 MB

No SBOM at hand?

What you get back

The results show on this page. Nothing to install.

SBOM quality
Each NTIA minimum element that is missing, such as the supplier name, a component version or a unique identifier.
Known vulnerabilities
Components matched against known advisories, with the top findings sorted by EPSS.
Components and licenses
How many components the SBOM lists, how many are vulnerable and which licenses they use.

From one file to every release

The analyzer shows what is in one SBOM today. SBOM Observer keeps all of them, keeps checking them and enforces your policies on every build.

Free SBOM AnalyzerSBOM Observer
SBOMs
One file at a time
Every SBOM from your pipelines and suppliers, kept per release
Vulnerabilities
Checked once, when you upload
Monitored continuously against OSV, GitHub Advisories and NVD
SBOM quality
NTIA minimum elements
NTIA and your own policies, enforced in CI/CD
Triage
Top findings sorted by EPSS
VEX decisions with owners, kept with the release
Impact
Component count and licenses
Impact graph across every application and release
Price
Free, no signup
From €69 per user per month

See everything SBOM Observer does →

Frequently asked questions

Which files can I upload?
One SBOM in CycloneDX or SPDX, as JSON or XML, up to 10 MB. Most SBOM generators produce one of these, including Syft, Trivy and cdxgen.
What are the NTIA minimum elements?
The minimum data an SBOM should contain according to the US National Telecommunications and Information Administration: supplier name, component name, version, unique identifiers, dependency relationships, the author of the SBOM data and a timestamp. The analyzer reports each missing field as a quality issue.
How are vulnerabilities ranked?
By EPSS, the Exploit Prediction Scoring System, which estimates how likely a vulnerability is to be exploited. The ones most likely to be exploited come first.
Do I need an account?
No. The analyzer is free and needs no signup. To keep SBOMs over time, monitor them and run policies in CI/CD, you need SBOM Observer.

Keep the SBOM for every release

The analyzer checks one file. SBOM Observer keeps every SBOM you build or buy per release, and checks it against new advisories as they are published.

SBOM Observer attestations: imported CycloneDX SBOMs with their status, type and component count