SBOM
The SBOM you can search the day a CVE drops.
Built from the data the install-path inventory already collects: snapshot at quarantine, queryable by CVE, CycloneDX 1.6 with real dependency edges.
Dependency edges
Direct and transitive, as CycloneDX 1.6 edges
dependsOn lists direct children only; a consumer walks the graph for
transitive paths. Current as of the last install through the proxy.
"components": [
{ "type": "library", "name": "express", "version": "4.19.2", "purl": "pkg:npm/express@4.19.2" },
{ "type": "library", "name": "body-parser", "version": "1.20.2", "purl": "pkg:npm/body-parser@1.20.2" },
{ "type": "library", "name": "bytes", "version": "3.1.2", "purl": "pkg:npm/bytes@3.1.2" }
],
"dependencies": [
{ "ref": "pkg:npm/express@4.19.2", "dependsOn": ["pkg:npm/body-parser@1.20.2"] },
{ "ref": "pkg:npm/body-parser@1.20.2", "dependsOn": ["pkg:npm/bytes@3.1.2"] }
] Compliance footprint
An export auditors and agents accept
| Formats | CycloneDX 1.6 (default), SPDX 2.3 |
|---|---|
| Scope | one repo, or the whole org |
| Snapshot | pinned at quarantine; a re-export six months later matches byte for byte |
| Edges | direct vs transitive encoded in CycloneDX dependency edges |
| Query | by CVE, license, package name, transitive depth |
| Audit | every export is an audit-log row: who, scope, snapshot, hash |
| Agents | chainsaw_export_sbom(), chainsaw_query_affected_packages() over MCP |
Stop hand-rolling SBOMs the day before an audit
See your SBOM in 15 minutes
The free tier includes the SBOM read view and search. Export and snapshot retention scale with the paid tiers.