Introduction
BomLoom is an open source platform to manage Software Bills of Materials, vulnerabilities and licenses.
BomLoom collects the SBOMs of your software, keeps track of the vulnerabilities affecting their components and checks their licenses against your policies.
BomLoom is in early development. Nothing is stable yet.
Features
- BOM management: import, version and browse SBOMs (CycloneDX first).
- Vulnerability management: match components against advisory sources (OSV first) and triage findings.
- License management: evaluate component licenses against policies based on SPDX identifiers.