Skip to main content
A Software Bill of Materials (SBOM) is a machine-readable inventory of the dependencies in your project. MergeGuide generates one from your dependency manifests in the standard CycloneDX and SPDX formats.

Generate an SBOM

Supported formats

List them anytime:

Supported manifests

sbom generate reads these dependency manifests: By default, development dependencies are excluded. Include them with --include-dev.

Options

See mergeguide sbom.

Scan dependencies for vulnerabilities

An SBOM inventories your dependencies; to check them against known vulnerabilities, run the vulnerability scanner:
See Running scans.

Next steps

OSCAL export

Export NIST OSCAL compliance evidence.

Compliance overview

How evidence fits your audit.