Nobuf

SBOM Supply Chain Explorer

Local analysis · optional OSV

Validate CycloneDX, SPDX and Syft SBOMs, explore dependencies, compare releases, and optionally query OSV.

Paste CycloneDX JSON/XML, SPDX JSON, or Syft JSON…

Parsing, graphing and comparison stay local. Only an explicit OSV scan sends up to 500 deduplicated versioned PURLs—not the SBOM, filenames, hashes, licenses or graph.

Ready to explore an SBOM

Open CycloneDX, SPDX or Syft evidence to inventory components, inspect dependency completeness and compare releases.

How to use it

  1. 01

    Open an SBOM

    Load a bounded CycloneDX, SPDX or Syft document and normalize its components, identifiers, licenses, hashes and relationships locally.

  2. 02

    Inspect supply-chain evidence

    Explore dependency roots and depths, broken edges, completeness dimensions, embedded vulnerabilities and release differences.

  3. 03

    Query or export deliberately

    Optionally send only versioned PURLs to OSV, then export local CSV, Markdown or redacted JSON evidence.

Frequently asked questions

What leaves the browser during an OSV scan?

Only up to 500 deduplicated versioned PURLs are sent after you click Scan. The complete SBOM, filenames, hashes, licenses and graph are not uploaded.

Does no reported vulnerability mean the project is safe?

No. Coverage, versions, aliases, database freshness and undisclosed issues all matter. The result is evidence for review, not proof of safety.

Does the dependency graph prove runtime reachability?

No. SBOM edges describe declared relationships and may be incomplete. Runtime loading, build options and application behavior require additional analysis.

Are license results legal advice?

No. The editor inventories identifiers and flags unknown expressions. Obligations and compatibility depend on source, distribution and jurisdiction and require qualified review.

Keep working with other focused browser utilities.

All tools

Local by default; remote data sources are clearly disclosed.

© 2026 Nobuf

Nobuf

Fast, local-first utilities powered by your browser.