SBOM

The SBOM you can search the day a CVE drops.

Built from the data the install-path inventory already collects: snapshot at quarantine, queryable by CVE, CycloneDX 1.6 with real dependency edges.

Dependency edges

Direct and transitive, as CycloneDX 1.6 edges

dependsOn lists direct children only; a consumer walks the graph for transitive paths. Current as of the last install through the proxy.

"components": [
  { "type": "library", "name": "express", "version": "4.19.2", "purl": "pkg:npm/express@4.19.2" },
  { "type": "library", "name": "body-parser", "version": "1.20.2", "purl": "pkg:npm/body-parser@1.20.2" },
  { "type": "library", "name": "bytes", "version": "3.1.2", "purl": "pkg:npm/bytes@3.1.2" }
],
"dependencies": [
  { "ref": "pkg:npm/express@4.19.2", "dependsOn": ["pkg:npm/body-parser@1.20.2"] },
  { "ref": "pkg:npm/body-parser@1.20.2", "dependsOn": ["pkg:npm/bytes@3.1.2"] }
]

Compliance footprint

An export auditors and agents accept

FormatsCycloneDX 1.6 (default), SPDX 2.3
Scopeone repo, or the whole org
Snapshotpinned at quarantine; a re-export six months later matches byte for byte
Edgesdirect vs transitive encoded in CycloneDX dependency edges
Queryby CVE, license, package name, transitive depth
Auditevery export is an audit-log row: who, scope, snapshot, hash
Agentschainsaw_export_sbom(), chainsaw_query_affected_packages() over MCP

Stop hand-rolling SBOMs the day before an audit

See your SBOM in 15 minutes

The free tier includes the SBOM read view and search. Export and snapshot retention scale with the paid tiers.