sbom-tool/sbom-tools
Semantic SBOM/CBOM diff, quality scoring, and TUI analysis tool for CycloneDX/SPDX — covering component changes, dependency shifts, license conflicts, vulnerabilities, cryptographic inventory grading, and PQC compliance (CNSA 2.0, NIST IR 8547).
GitHub repository with 224 stars and 13 forks.
Language: Rust
Topics: vulnerability-management, sbom, cbom, cyclonedx, sarif, software-supply-chain-security, spdx, vex, appsec, sbom-tool