<--Back to Projects List

SBOM Play

🚧 Work in Progress
This page is currently being updated as and when Anant gets time. Once it is fully updated, this message will be removed.
Image for SBOM Play

TL;DR

🚀 What it does: Browser-based SBOM analysis tool for GitHub repositories

💡 Best for: Developers and security teams analyzing software supply chains

🔍 Key features: Dependency tracking, supply chain analysis, privacy-aware processing


SBOM Play is a browser-based, privacy-aware tool for analyzing Software Bill of Materials (SBOM) data from GitHub repositories, organizations, and users. This innovative web application provides comprehensive dependency analysis and supply chain security insights without requiring server-side processing.

Project Overview

SBOM Play addresses the critical need for software supply chain security analysis by providing a client-side tool that can analyze dependency data from GitHub repositories. The tool helps organizations understand their software dependencies, track usage patterns, and identify potential security risks in their supply chain.

Key Features

🔍 Comprehensive SBOM Analysis

🛡️ Privacy-Aware Design

📊 Advanced Analytics

🔧 Export and Management

Technical Implementation

Technology Stack

Core Components

Usage

Quick Start

  1. Open https://cyfinoid.github.io/sbomplay/ in your browser
  2. Optionally enter a GitHub Personal Access Token for better rate limits
  3. Enter an organization name or username to analyze
  4. Click “Analyze Organization or User” to start the analysis
  5. View results and export data as needed

Supported Dependency Formats

Advanced Features

Rate Limit Management

Storage Management

Multi-Organization Support

Use Cases

SBOM Play is valuable for:

Security Operations

Development Teams

DevOps and Operations

Project Impact

Community Adoption

Innovation Value

Technical Architecture

Client-Side Architecture

Data Processing

Deployment and Development

GitHub Pages Deployment

Development Workflow

Future Development

Planned Features

Community Contributions


A privacy-aware, browser-based tool for Software Bill of Materials analysis and supply chain security assessment

Part of Cyfinoid Research’s commitment to advancing software supply chain security