Your Security Artifact Hub
From zero to SBOM hero. Generate, manage, and share SBOMs and compliance documents with your stakeholders.
Our Mission
We're building the infrastructure for a more transparent software world. From SBOMs to AI BOMs, Bills of Materials are becoming the backbone of all compliance—and we make security artifacts easy to create, manage, and share, so trust flows seamlessly from vendor to buyer to auditor.
Zero to SBOM Hero
Build high-quality SBOMs directly in your CI pipeline with our open source action. Once generated, SBOMs are automatically uploaded to sbomify where you can manage releases (including complex hierarchies) and share the latest software versions with stakeholders—publicly or privately via your Trust Center. No more manual SBOM distribution or version confusion.
Transparency That Builds Trust
Share SBOMs, compliance documents, and security artifacts with stakeholders in a standardized way. Your trust center can be hosted on your own domain and supports both web portal access and standardized SBOM formats for automated consumption. Compliance documents are expressed programmatically alongside your SBOMs.
Store, Analyze & Enrich
sbomify is designed not only to hold your security artifacts but also to send them off for analysis. We integrate with CI/CD pipelines (GitHub, GitLab, Bitbucket), analysis tools like Google OSV and Dependency Track, and enrichment platforms such as Ecosyste.ms. Your security artifacts flow seamlessly from generation through analysis and enrichment, giving you actionable insights without manual work.
CRA is Coming. Ready or Not.
The EU's Cyber Resilience Act (CRA) is now in force, with mandatory reporting starting September 11, 2026. Whether you sell to European customers or not, CRA compliance is becoming a baseline expectation for B2B software.
Combined with US Executive Order 14028 requiring SBOMs for federal procurement, the message is clear: transparency isn't optional anymore. sbomify helps you meet these requirements efficiently, whether you need public trust centers, automated SBOM generation, or compliance reporting.
Learn More About CRASelf-Host or Cloud
sbomify gives you the flexibility to run it yourself or let us run it for you. Find us on GitHub to self-host for complete control over your data and infrastructure, or use our managed cloud service for zero-maintenance convenience.
Either way, you get the same powerful SBOM and compliance document management, support for CycloneDX and SPDX formats, and seamless integrations with your existing tools. No vendor lock-in, no compromises.
Latest blog posts
Announcing sbomify v0.25: The One with Attestations
Software supply chain security is not just about knowing what is in your software. It is about proving that knowledge is authentic and has not been tampered with....
Announcing sbomify-action v0.11: The One Where They Go to PyPI
With v0.11, sbomify-action is no longer tied to your CI/CD pipeline. Install it anywhere with pip install sbomify-action and generate enriched SBOMs on your laptop, in your build...
Announcing sbomify v0.24: The One with All the Plugins
Today marks a pivotal release for sbomify. With v0.24, we are laying the foundation for what will become a fully extensible, plugin-based platform. This release introduces our new...