Import
Upload a CycloneDX or SPDX inventory, or import an inventory from GitHub. The GitHub import does not fetch your source code.
SBOM & inventory
Import CycloneDX or SPDX, or connect GitHub. Review inventory quality and component identity before using the data for vulnerability assessments.
Upload a CycloneDX or SPDX inventory, or import an inventory from GitHub. The GitHub import does not fetch your source code.
See missing versions and identifiers, resolve component identity and understand where vulnerability matching has limits.
Maintain components per release and make changes visible, including embedded and C libraries when the inventory identifies them.
Inventory excerpt