{"repo":"devops-kung-fu/bomber","free":true,"listed":false,"github":"https://github.com/devops-kung-fu/bomber","clone":"git clone https://github.com/devops-kung-fu/bomber.git","description":"Scans Software Bill of Materials (SBOMs) for security vulnerabilities","language":"Go","stars":624,"topics":["spdx","cyclonedx","gomodule","sbom","supply-chain","oss","supplychain","vulnerability-scanners","syft","devsecops"],"license":"MPL-2.0","category":"security-tools","readme_excerpt":"bomber is an application that scans SBOMs for security vulnerabilities. Overview So you've asked a vendor for an Software Bill of Materials (SBOM) for one of their closed source products, and they provided one to you in a JSON file... now what? The first thing you're going to want to do is see if any of the components listed inside the SBOM have security vulnerabilities, and what kind of licenses these components have. This will help you identify what kind of risk you will be taking on by using the product. Finding security vulnerabilities and license information for components identified in a SBOM is exactly what bomber is meant to do. bomber can read any JSON or XML based CycloneDX format, or a JSON SPDX or Syft formatted SBOM, and tell you pretty quickly if there are any vulnerabilities. Table of Contents - Open vs. Closed Source - Purpose - Supported SBOM formats - Providers - Provider Support - Provider Documentation - Installation - Mac - Linux - Using bomber - Single SBOM scan - Entire folder scan - Output Formats - HTML Output - JSON Output - Markdown Output - Ignoring Vulnerabilities - Filtering Output - Data Enrichment - Exploit Prediction Scoring System (EPSS) - Advanced stuff - Scanning SBOMs from STDIN - Environment Variables - Experimental Features - Highest Severity Return Codes (Experimental) - OpenAI AI Enriched HTML Report Output - Messing around - Notes - Contributing - Software Bill of Materials - Sponsors - Credits Open vs. Closed Source Software can eith","default_branch":null,"files":null,"tree":[],"storefront":"/r/devops-kung-fu","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/devops-kung-fu/bomber/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}