Skip to content

SBOM Play

Analyse SBOMs from a GitHub org, user, repo, or URL — all in your browser.

Resume Analysis

You have a pending analysis that was interrupted by a rate limit. You can resume it now.

Drag & drop SBOM files here

or click to select files (multiple files supported)

Supported: SPDX JSON, CycloneDX JSON
Files to Analyze 0
Optional: GitHub token for higher rate limits
Note: GitHub tokens are not saved or persisted. You will need to provide your token each time you use the application.
Analysis Progress
0%
Initializing analysis...
Dependency Resolution by Ecosystem:
Started:
Elapsed: 0s
Total packages processed: 0
Finished:
Total Time:
Help & tips

Accepts an org (microsoft), user (torvalds), a single repo (microsoft/vscode), or a GitHub URL. Without a token you get 60 requests/hour; with one, 5,000.

See About for full methodology, input formats, storage details, and the rate-limit handling flow.

Analysis Results
Statistics Dashboard

Loading statistics...

SBOM Quality Assessment
Top 5 Most Commonly Used Dependencies
Top 5 Dependencies with Version Sprawl
License Distribution
Portfolio Snapshot

Crunching the data…

Background Analysis Running
Analyzing...