scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
-
Updated
Oct 2, 2026 - JavaScript
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.
Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data
Create CycloneDX Software Bill of Materials (SBOM) from Node.js Yarn projects.
GitHub action to generate a CycloneDX SBOM for Node.js
GitHub action to generate a CycloneDX SBOM for Python
GitHub action to generate a CycloneDX SBOM for .NET
GitHub action to generate a CycloneDX SBOM for Go modules
Lockfile-first SBOM and AI BOM generator and CVE exposure search. CLI, GitHub Action, and hosted API. CycloneDX 1.6 + SPDX 2.3.
GitHub action to generate a CycloneDX SBOM for PHP Composer
To associate your repository with the sbom-generator topic, visit your repo's landing page and select "manage topics."