PROFILE-AWARE VALIDATION
Machine-readable checks align CycloneDX fields with BSI TR-03183-2 v2.1.0 while keeping unsupported or ambiguous cases explicit.
WORK · I
SUPPLY-CHAIN SECURITY · 0.3.0
An SBOM security workspace that validates component inventory, evaluates profile quality, and surfaces known vulnerabilities without mixing mutable findings into the source document.
01
CycloneDX JSON 1.6 or 1.7
Schema and BSI profile rules
OSV or deterministic demo data
Web report, JSON, or SARIF 2.1.0
02
demo-shop.cdx.json
supplyguard demo-shop.cdx.json --provider demo --format jsonCRITICAL · 1HIGH · 1
VALIDATION ERRORS0
DATA COMPLETEYES
Current result from the repository's bundled CycloneDX demo and deterministic provider. No network request is required.
03
Machine-readable checks align CycloneDX fields with BSI TR-03183-2 v2.1.0 while keeping unsupported or ambiguous cases explicit.
Upload size, JSON depth, component traversal, OSV pages, and vulnerability details are bounded and reported instead of silently truncated.
The database-free CLI emits stable exit codes and can fail on severity, validation errors, or incomplete vulnerability data.
Inventory remains inside the SBOM. Mutable vulnerability findings stay in the analysis report and can be exported as JSON or SARIF.
04
05
Profile-aligned technical checks are not official BSI certification.
SPDX is outside the current scope; the implemented input is CycloneDX JSON.
Live OSV matching requires valid package URLs and discloses them to OSV.
A public multi-tenant deployment still requires identity, authorization, retention, and edge abuse controls.
SOURCE · DOCUMENTATION · MIT