Open source sbom projects
Every project in the registry tagged sbom, ranked by real GitHub adoption.
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
GUAC aggregates software security metadata into a high fidelity graph database.
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. B
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Related tags
Frequently asked questions
How many open source sbom projects are there?
This registry tracks 5 projects tagged sbom, with 8,695 GitHub stars between them. The most-adopted is retire.js at 4,173 stars.
Are these sbom projects free to use?
Yes — 5 of the 5 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which sbom project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these sbom projects still maintained?
4 of the 5 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.