CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Top SBOM GitHub Repositories & Tools (2026)
Discover the most starred and trending open source tools tagged with #sbom.
A suite of tools to automate software compliance checks.
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-of-Materials (SBOM) for supported binaries.
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
A secure, high-performance, multi-tenant platform for remote App ”Hosting“ and ”Computing“
The Airgap Native Package Manager for Kubernetes
ReARM - Release Governance Platform
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.