Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
@sbom-tool

SBOM-Tools

Making SBOMs readable and actionable.

sbom-tools

Making SBOMs readable and actionable.

We build open-source tools for software supply chain transparency and CI/CD security hardening. Everything we ship is designed to be production-ready, security-first, and easy to integrate into existing workflows.

Projects

sbom-tools — Rust CLI for semantic SBOM diff, validation, quality scoring, vulnerability enrichment, and compliance checking. Supports CycloneDX and SPDX formats. Compliance profiles for NTIA, CRA, FDA, and EO 14028.

sbom-tools-action — GitHub Action for sbom-tools with SHA-256 checksum verification, SLSA/Sigstore provenance verification (required by default), and zero expression injection surface. Hardened against supply chain attacks like the March 2026 Trivy tag hijacking.

gh-guard — Claude Code plugin for CI/CD supply chain hardening. Generates SHA-pinned workflows, Trusted Publishing, SLSA L3 provenance, and Scorecard optimization for Rust projects. Includes dangerous workflow detection and incident response guidance.

Links

Pinned Loading

  1. sbom-tools sbom-tools Public

    Semantic SBOM/CBOM diff, quality scoring, and TUI analysis tool for CycloneDX/SPDX — covering component changes, dependency shifts, license conflicts, vulnerabilities, cryptographic inventory gradi…

    Rust 225 13

  2. gh-guard gh-guard Public

    CI/CD supply chain hardening plugin for Claude Code, designed for Rust projects

    Shell 14 2

  3. sbom-tools-action sbom-tools-action Public

    GitHub Action for installing and running sbom-tools — semantic SBOM diff, validation, and quality scoring

    4

Repositories

Loading
Type
Select type
Language
Select language
Sort
Select order
Showing 5 of 5 repositories

Top languages

Loading…

Most used topics

Loading…

Morty Proxy This is a proxified and sanitized view of the page, visit original site.