Free SBOM Analyzer
Drop an SBOM below and see what is in it: quality issues, known vulnerabilities, components and licenses. Free, no signup.
Drop your SBOM here
or
CycloneDX or SPDX · JSON or XML · up to 10 MB
No SBOM at hand?
What you get back
The results show on this page. Nothing to install.
- SBOM quality
- Each NTIA minimum element that is missing, such as the supplier name, a component version or a unique identifier.
- Known vulnerabilities
- Components matched against known advisories, with the top findings sorted by EPSS.
- Components and licenses
- How many components the SBOM lists, how many are vulnerable and which licenses they use.
payments-api-4.2.1.cdx.json
payments-api @ 4.2.1
Components
Quality issues
Vulnerabilities
Licenses
Quality issues
NTIA Minimum Elements for SBOM
metadata.supplier is missing (NTIA Supplier Name)
Top vulnerabilities by EPSS
CVE-2021-44228
Critical 10org.apache.logging.log4j:log4j-core 2.14.1
Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
CVE-2023-44487
High 7.5org.eclipse.jetty.http2:http2-server 9.4.18
HTTP/2 Rapid Reset allows denial of service
From one file to every release
The analyzer shows what is in one SBOM today. SBOM Observer keeps all of them, keeps checking them and enforces your policies on every build.
- SBOMs
- One file at a time
- Every SBOM from your pipelines and suppliers, kept per release
- Vulnerabilities
- Checked once, when you upload
- Monitored continuously against OSV, GitHub Advisories and NVD
- SBOM quality
- NTIA minimum elements
- NTIA and your own policies, enforced in CI/CD
- Triage
- Top findings sorted by EPSS
- VEX decisions with owners, kept with the release
- Impact
- Component count and licenses
- Impact graph across every application and release
- Price
- Free, no signup
- From €69 per user per month
Frequently asked questions
Which files can I upload?
What are the NTIA minimum elements?
How are vulnerabilities ranked?
Do I need an account?
Keep the SBOM for every release
The analyzer checks one file. SBOM Observer keeps every SBOM you build or buy per release, and checks it against new advisories as they are published.
