Skip to content

Latest commit

 

History

History

SwiftBOM

SwiftBOM SBOM demo tool

SwiftBOM a SBOM generator tool here is part of CERT's work in supporting SBOM generation efforts for Proof-of-Concepts and Demo purposes. This tool is currently being explored by Healthcare Proof of Concept teams for their PoC efforts.

The SwiftBOM has some live demo that you can run to see SBOM generation supported by the tool. The tool also has some limited import capability to accept SBOM input and provide multiple format outputs.

SBOM Formats

SwiftBOM currently generates SBOM in SPDX, CycloneDX and SWID formats. A tree graph is also generated by SwiftBOM that can be downloaded as a PNG file to quickly visualize relationships between components in an SBOM. Currently the tool uses CONTAINS as the default relationship mode (SWID Relationships)[https://spdx.github.io/spdx-spec/7-relationships-between-SPDX-elements/#71-relationship]. A generated SBOM in all three formats is currently a standalone document and does not support external relationships.

Data collection and privacy

None of the data you enter or simulate is sent back to the server. The data sits on the client-side. The tools to generate SPDX, SWID and CycloneDX can all work even if your browser is disconnected from the network after loading the website.

Looking for SBOM for this software ?

Look in self-sbom folder, currently has no assertions or hash signatures just a full list of assembled software