Skip to content
sbomtriage
ProductCRAVendor reviewExplore appMethod
Sign inScan a file

Sign in to your workspace

Save repository scans and uploaded SBOMs, review recommended upgrades, and track changes in one place.

Continue with GitHub Continue with Google
or use an email address

By continuing, you agree to the Terms and Acceptable use, and confirm you’re using sbomtriage for work. The Privacy notice explains how your data is handled.

  • No SBOM neededPoint it at a repository and it finds the manifests for you, reading twelve lockfile and manifest formats across seven ecosystems into one inventory.
  • Vendor SBOMs tooUpload the SBOM a supplier emailed you and track it next to your own code.
  • See what changes over timeCreate an account and answer four questions to get ten projects, scans whenever you want, daily monitoring and 90 days of history. It’s free during early access.
sbomtriage

A short, ranked fix plan from an SBOM, a lockfile or a repository, with the reason next to each decision.

  • The uploaded file is never written to disk.
  • Anonymous reports are deleted after 24 hours. Project history is kept for 90 days.
  • No analytics, no advertising, no third-party tracking.

Product

  • Scan a file
  • Example workspace
  • Early access
  • Changelog

Use cases

  • Your own code
  • EU Cyber Resilience Act
  • Supplier SBOMs
  • Look up a CVE

Resources

  • Documentation
  • How it ranks
  • Status
  • Example report

Trust

  • Security
  • Privacy
  • Terms
  • Subprocessors
  • Data sources

Company

  • Contact
  • Legal
  • Data processing
  • Imprint

© 2026 sbomtriage. Vulnerability data from OSV.dev, CISA KEV and FIRST EPSS.

Status