Open source sbom projects

Every project in the registry tagged sbom, ranked by real GitHub adoption.

projects 5 combined stars ★ 8.7K refresh nightly
01 retire.js ★ 4.2K

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

last push4 days ago languageJavaScript licenseApache-2.0
02 guac ★ 1.5K

GUAC aggregates software security metadata into a high fidelity graph database.

last push27 hours ago languageGo licenseApache-2.0
03 dep-scan ★ 1.3K

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. B

last push1 months ago languagePython licenseMIT
04 cdxgen ★ 1.1K

Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI

last pushyesterday languageJavaScript licenseApache-2.0
05 bomber ★ 624

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

last push7 months ago languageGo licenseMPL-2.0

Related tags

← all tags

Frequently asked questions

How many open source sbom projects are there?

This registry tracks 5 projects tagged sbom, with 8,695 GitHub stars between them. The most-adopted is retire.js at 4,173 stars.

Are these sbom projects free to use?

Yes — 5 of the 5 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which sbom project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these sbom projects still maintained?

4 of the 5 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.