About
ndaal SBOM Auditor v1.4.11
A single-binary web application to investigate uploaded and imported SBOM (Software Bill of Materials) files. SBOMs are analysed with an ensemble of independent tools — syft, trivy, grype, osv-scanner and bomber — and the normalised findings are presented in one local, offline UI. Copy the binary, run it, and audit your software supply chain; no installation and no network access required.
Analyzer ensemble
syft— generatorgrype— scannertrivy— scannerosv-scanner— scannerbomber— scannerbomdrift— supply-chain driftinspektr_cli— scannershieldbom— scannerprovenant— licence/provenance
Features
- Single binary — the complete UI ships inside the executable
- Investigate uploaded and imported SBOM files
- Memory-safe Rust,
#![forbid(unsafe_code)] - HTTPS only — TLS 1.3 via rustls with post-quantum key exchange
- No CDN, no telemetry, localhost only by default
Project
ndaal SBOM Auditor by ndaal, Cologne.