sbomqs: The Comprehensive SBOM Quality & Compliance Tool
-
Updated
Aug 31, 2026 - Go
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.
Utility that provides an API platform for validating, querying and managing BOM data
Hermeto is a CLI tool that prefetches project dependencies for hermetic container builds.
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team
SBOM generation, enrichment, and management for CI/CD. CycloneDX & SPDX, from lockfiles or containers.
Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.
SBOM-in-a-Box is a unified platform to promote the production, consumption, and utilization of Software Bills of Materials.
SBOMinify is a GitHub Action to capture and list installed packages and their versions in a Docker image, generating Software Bill of Materials (SBOM) files. This action leverages some special technics to scan Docker images and output SBOM files in both table and JSON formats.
To associate your repository with the sbom-quality topic, visit your repo's landing page and select "manage topics."