Tooling

The tools in this field fall into two families that do different jobs and are not substitutes. Confusing them is the most expensive mistake in the programme; the page Generate and steer explains why.

Generators Platforms
Level Application, one artefact Organisation, the portfolio
Question “What is inside this artefact?” “Which of your products contain this component?”
Trigger A build A newly published vulnerability
Output A CycloneDX or SPDX file Dashboards, alerts, reports, API
Examples Syft, Trivy, Grype, cdxgen, osv-scanner OWASP Dependency-Track, Snyk, FOSSA, Black Duck

How to read the profiles

Each tool is described against the same template: vendor, licence and business model, level, supported formats, ecosystem coverage, vulnerability sources, licence detection, VEX support, integrations, deployment mode and data sovereignty, strengths, limits, and a verdict for your context.

Caveat. These profiles describe categories of product and their structural properties, not a snapshot of the market: versions, pricing and coverage change. Any purchasing decision must rest on an evaluation run against your own artefacts, following the protocol in Selection criteria.

The position adopted

Two principles guide the target tooling:

  1. An open, standardised generator, so the SBOMs you produce stay portable and independent of whichever platform consumes them. A proprietary SBOM is a liability.
  2. A steering platform, starting with a self-hostable option to validate the processes at zero software cost, before deciding on a commercial product if scale or legal requirements justify it.

In this section

  • Cyber

    SBOM generators

    Application-level tools: Syft, Grype, Trivy, cdxgen, osv-scanner, ScanCode, OSS Review Toolkit and native build-chain plugins.

  • Cyber

    Steering platforms

    Organisation-level tools: OWASP Dependency-Track, Snyk, FOSSA, Black Duck, Mend, Sonatype, JFrog Xray, GUAC — and what really separates them.

  • Leadership

    Selection criteria and evaluation protocol

    A weighted grid, an evaluation protocol run against your own artefacts, and the recommended tooling architecture.