Software Bill of Materials
v5.18.1
Search this version
Analyze CycloneDX/SPDX report file
Copy Markdown
Open in ChatGPT
Open in Claude
In the SBOM area, CycloneDX is typically used for vulnerability tracking, whereas SPDX focuses more on software license information. The SBOM module can take these reports, then adding any missing components such as CVE details, license details, and library information. This process produces a fully enriched SBOM that combines both security and compliance insights for more accurate analysis and reporting.


Supported format:
CyclonceDX JSON v1.4, v1.5, v1.6, v1.7
SPDX JSON v2.3, v3.0.1
Last updated on
Was this page helpful?
Next to read:
JSON responseSoftware Bill of Materials
Software Bill of Materials