CYCLONEDXAUDIT · PROFESSIONAL BROWSER TOOL

An SBOM needs more than components; its references and dependency edges must resolve.

Audit CycloneDX JSON versions, component identities, bom-ref uniqueness, dependency targets, ungraphed components, licenses, and hash fields locally.

Open the workbench
Processed locally
Local report studioPreview · Markdown · JSON · SHA-256
SHA-256

Uses only the currently visible result summary, never input controls or original files; the fingerprint is also calculated locally.

Local analysis checkpointsUp to 5 · saved only when you choose

    Stores only the visible result summary, time, and an optional short label; imported files and input controls are never stored. Imports must match this tool and stay under 128KB; comparison also stays on this device.

    01

    Component and bom-ref uniqueness

    02

    Dependency reference integrity and degree

    03

    License, hash, and vulnerability counts

    This is a bounded common-field and reference preflight, not full schema, license-compliance, vulnerability-truth, signature, or supply-chain risk validation.

    Read the source

    NO ACCOUNT · LOCAL PROCESSING · EXPORTABLE

    Professional tools can still be quiet and transparent.

    Read privacy and limitations →