sbomqs: The Comprehensive SBOM Quality & Compliance Tool
-
Updated
Jul 27, 2026 - Go
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.
Utility that provides an API platform for validating, querying and managing BOM data
Hermeto is a CLI tool that prefetches project dependencies for hermetic container builds.
Reference GitHub Workflows for SBOM generation from the CISA SBOM Generation Reference Implementation Tiger Team
About standalone, Kubernetes-native Software Bill of Materials (SBOM) visualization and governance platform
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
SBOM-in-a-Box is a unified platform to promote the production, consumption, and utilization of Software Bills of Materials.
SBOMinify is a GitHub Action to capture and list installed packages and their versions in a Docker image, generating Software Bill of Materials (SBOM) files. This action leverages some special technics to scan Docker images and output SBOM files in both table and JSON formats.
Add a description, image, and links to the sbom-quality topic page so that developers can more easily learn about it.
To associate your repository with the sbom-quality topic, visit your repo's landing page and select "manage topics."