{"repo":"rezmoss/sbomlyze","free":true,"listed":false,"github":"https://github.com/rezmoss/sbomlyze","clone":"git clone https://github.com/rezmoss/sbomlyze.git","description":"Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.","language":"Go","stars":24,"topics":["cyclonedx","devsecops","sbom","sbom-tool","security","spdx","syft","compliance","dependency-graph","drift-detection"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"sbomlyze git diff for your SBOM. Compare two Software Bills of Materials and see what changed between builds, versions, and releases. sbomlyze compares component hashes, not only version strings. When an attacker swaps a package without bumping its version, sbomlyze flags it. Generators and vulnerability scanners miss this. [![CI][ci-img]][ci] [![GitHub Marketplace][marketplace-img]][marketplace] [![GitHub Release][release-img]][release] [![Go Report Card][go-report-img]][go-report] [![OpenSSF Scorecard][scorecard-img]][scorecard] [![License: Apache-2.0][license-img]][license] [![Downloads][download-img]][download] See why this signal is different from a manifest or ordinary component diff in Manifest diff vs. SBOM diff vs. integrity drift. Generators make SBOMs and scanners find CVEs. sbomlyze tells you what changed between two SBOMs and whether to trust it. Run it after your generator: syft image:tag -o cyclonedx-json sbomlyze - --compliance analyzes and scores the generated SBOM without a temporary file. Compare it with a baseline to classify drift and gate your pipeline. GitHub Action quickstart Add [SBOMlyze Diff from GitHub Marketplace][marketplace] to compare a checked-in or separately generated SBOM with its git baseline. The immutable SHA below is the published v0.5.1 Action: The Action writes a Job Summary by default and can enforce policy, report integrity drift, upload SARIF, or maintain a single pull-request comment. See the complete Action reference for inputs, ","default_branch":null,"files":null,"tree":[],"storefront":"/r/rezmoss","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/rezmoss/sbomlyze/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}