Analyze CycloneDX/SPDX report file

In the SBOM ecosystem, CycloneDX is commonly associated with vulnerability tracking, while SPDX has historically focused on software license information. The SBOM engine can scan reports in either format and enrich them with any missing data, such as CVE details, license information, and library metadata. The result is a fully enriched SBOM that combines security and compliance insights for more accurate analysis and reporting.

Supported format:

  • CyclonceDX JSON v1.4, v1.5, v1.6, v1.7

  • SPDX JSON v2.3, v3.0.1