Scan your software

Drop an SBOM or a lockfile to get a ranked fix plan, or connect GitHub to follow a repository over time.

Upload an SBOM or lockfile

No account needed. Upload one file or several.

Drop files here, or click to browse

Add several at once, up to 20 MB. No account needed.

  • CycloneDX JSON
  • SPDX JSON
  • package-lock.json
  • package.json
  • yarn.lock
  • pnpm-lock.yaml
  • requirements.txt
  • Pipfile.lock
  • poetry.lock
  • Cargo.lock
  • go.mod
  • composer.lock
  • Gemfile.lock
  • packages.lock.json

Your report stays available for 24 hours. Sign in and save it to a project to track changes over time.

Start with your repository

Pick the public or private repositories you want to check. sbomtriage reads their dependency manifests and gives you a prioritised plan.

  • Select the repositories the app can access
  • Review findings and recommended upgrades
  • Compare changes across saved scans
Connect GitHub

Free during early access, once you’ve answered four questions: scan whenever you want, plus daily monitoring.