SBOM Play
Analyse SBOMs from a GitHub org, user, repo, or URL — all in your browser.
All analysis happens in your browser. No data is sent to any server.
Resume Analysis
You have a pending analysis that was interrupted by a rate limit. You can resume it now.
Drag & drop SBOM files here
or click to select files (multiple files supported)
Supported: SPDX JSON, CycloneDX JSON
Files to Analyze
0
Optional: GitHub token for higher rate limits
Note: GitHub tokens are not saved or persisted. You will need to provide your token each time you use the application.
Analysis Progress
Initializing analysis...
Dependency Resolution by Ecosystem:
Started:
Elapsed: 0s
Total packages processed: 0
Finished:
Total Time:
Help & tips
Accepts an org (microsoft), user (torvalds), a single repo (microsoft/vscode), or a GitHub URL. Without a token you get 60 requests/hour; with one, 5,000.
See About for full methodology, input formats, storage details, and the rate-limit handling flow.
Analysis Results
Statistics Dashboard
Loading statistics...
SBOM Quality Assessment
Top 5 Most Commonly Used Dependencies
Top 5 Dependencies with Version Sprawl
License Distribution
Portfolio Snapshot
Crunching the data…