Skip to main content

About

ndaal SBOM Auditor v1.4.11

A single-binary web application to investigate uploaded and imported SBOM (Software Bill of Materials) files. SBOMs are analysed with an ensemble of independent tools — syft, trivy, grype, osv-scanner and bomber — and the normalised findings are presented in one local, offline UI. Copy the binary, run it, and audit your software supply chain; no installation and no network access required.

Analyzer ensemble
  • syft — generator
  • grype — scanner
  • trivy — scanner
  • osv-scanner — scanner
  • bomber — scanner
  • bomdrift — supply-chain drift
  • inspektr_cli — scanner
  • shieldbom — scanner
  • provenant — licence/provenance
Features
  • Single binary — the complete UI ships inside the executable
  • Investigate uploaded and imported SBOM files
  • Memory-safe Rust, #![forbid(unsafe_code)]
  • HTTPS only — TLS 1.3 via rustls with post-quantum key exchange
  • No CDN, no telemetry, localhost only by default
Project

ndaal SBOM Auditor by ndaal, Cologne.