PRIVACY-FIRST WEB SBOM SCANNER & CHECKER
Audit Software Dependencies & Discover Vulnerabilities
Drag and drop your manifest, lockfile, or CycloneDX/SPDX JSON. File parsing runs locally in your browser; only package coordinates are matched against the OSV database.
Local Device ParsingNo Registration Required
Drag & Drop Dependency or SBOM Files Here
Or select files from your computer. Up to 5 files, 5MB per file.
Select Files
Supported formats: CycloneDX JSON (bom.json, cdx.json), SPDX JSON, package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, Pipfile.lock, poetry.lock, pom.xml, Cargo.lock, go.mod, composer.lock