SBOM tools: open-source generators, analysers and how to choose
SBOM tooling falls into a few distinct jobs: generating, validating, converting, scoring and analysing. This guide maps well-known open-source tools to those jobs and sets out criteria for choosing among them.
- No single tool does everything; most programmes combine a generator, a validator and an analysis platform.
- Generators differ in the ecosystems they understand and whether they read source, containers or binaries.
- Validation and quality-scoring tools check format conformance and minimum-field coverage, which are separate questions.
- Choose tools by ecosystem coverage, output formats, offline operation and how well they fit your pipeline.
The jobs SBOM tools do
"SBOM tool" covers several different functions. Separating them makes selection easier:
| Job | Question it answers | Examples (open source) |
|---|---|---|
| Generate | What components are in this source tree, image or binary? | Syft, cdxgen, Trivy, Microsoft SBOM Tool |
| Validate | Does this document conform to its format and to a field baseline? | CycloneDX CLI, SPDX tools-python, NTIA Conformance Checker |
| Score quality | How complete and useful is it? | sbomqs, sbom-scorecard |
| Convert and merge | Can I move between formats and combine documents? | CycloneDX CLI, protobom |
| Analyse | Which components are vulnerable, outdated or non-compliant? | Grype, Trivy, OSV-Scanner, OWASP Dependency-Track, GUAC |
Generators
- Syft is a CLI and Go library that generates SBOMs from container images, filesystems and archives across many packaging ecosystems, with CycloneDX, SPDX and its own JSON output. It is Apache-2.0 licensed [1].
- cdxgen, a CycloneDX project, generates CycloneDX BOMs for many languages and package managers and for container images, offers SPDX 3.0.1 JSON-LD export, and can produce CBOM, OBOM, SaaSBOM and other BOM types. It can also run as a server [2].
- Trivy is a security scanner that can generate SBOMs in CycloneDX and SPDX formats [3].
- Microsoft SBOM Tool creates SPDX 2.2 and SPDX 3.0 SBOMs for build artefacts on Windows, Linux and macOS, and includes a validate command; it is MIT licensed [4].
Validators and converters
- CycloneDX CLI validates, converts, diffs, merges, signs and verifies BOMs. It converts between CycloneDX XML, JSON and Protobuf and SPDX JSON 2.3, and warns that SPDX–CycloneDX conversion can lose information [5].
- SPDX tools-python parses, validates and converts SPDX 2.2 and 2.3 documents across tag-value, RDF, JSON, YAML and XML, with experimental SPDX 3.0 write support [6].
- NTIA Conformance Checker checks whether an SPDX SBOM contains the NTIA minimum elements, and optionally CISA's 2024 Framing Software Component Transparency baseline [7].
- protobom, an OpenSSF sandbox project, provides a format-neutral representation for reading and writing SPDX and CycloneDX [8].
Quality scoring
sbomqs scores SPDX and CycloneDX SBOMs on a 0–10 scale across categories such as identification, provenance, integrity, completeness and licensing, and runs compliance checks against NTIA, BSI TR-03183-2 and other profiles [9]. sbom-scorecard also scores SBOMs, but its repository describes it as work in progress with no stable release [10]. More on this in SBOM validation.
Analysis
- Grype scans container images, directories and SBOMs for known vulnerabilities and supports OpenVEX for filtering results [11].
- Trivy accepts CycloneDX and SPDX SBOMs as a scan target for vulnerabilities and licences [12].
- OSV-Scanner checks dependencies against the OSV.dev database and supports offline scanning against a local copy [13].
- OWASP Dependency-Track is a continuous component-analysis platform that consumes CycloneDX SBOMs and VEX, draws on several vulnerability sources and has a policy engine and API [14].
- GUAC, an OpenSSF project, aggregates SBOMs, SLSA attestations, OSV data, Scorecard results and VEX into a graph for querying [15].
How to choose
- Ecosystem coverage. Test each generator on your real repositories and images. Missing lockfile support is the most common source of incomplete SBOMs.
- Lifecycle stage. Decide whether you need source, build, analysed or runtime SBOMs; see SBOM generation.
- Output fields. Check hashes, licences, purls and dependency relationships against the fields you must supply, such as the CERT-In 21 fields.
- Formats and versions. Confirm the CycloneDX and SPDX versions your consumers accept.
- Offline operation. Air-gapped environments need tools that run without network calls and vulnerability data that can be mirrored.
- Pipeline fit. Prefer tools that return non-zero exit codes on failure so a pipeline can stop a release.
- Project health. Check release cadence, maintainers and licence before standardising.
Tools produce and check documents. Governing them across hundreds of applications and suppliers is a platform question; see SBOM platforms.
How IntelliXBOM helps
IntelliXBOM generates SBOMs and ingests CycloneDX and SPDX documents from any of these tools, validates them against required-field policies, and keeps version history. It then correlates components with vulnerabilities, known-exploited lists, licences and end-of-life data, and links them to business services.
Frequently asked questions
What is the best open-source SBOM tool?
It depends on the job and your ecosystems. Generators, validators, quality scorers and analysis platforms solve different problems, so most teams combine several and test generators against their own repositories and images.
Can one tool generate both CycloneDX and SPDX?
Yes. Syft and Trivy can output both, and cdxgen produces CycloneDX with an SPDX 3.0.1 export. Converters such as CycloneDX CLI also translate between them, with some possible loss of information.
Do SBOM tools work offline?
Many generators run locally without network access. Vulnerability analysis needs a data feed; some tools, such as OSV-Scanner, support scanning against a locally downloaded database.
Sources
- Syft, CLI tool and library for generating SBOMsanchore/syft (GitHub)github.com/anchore/syft
- cdxgen, CycloneDX GeneratorCycloneDX/cdxgen (GitHub)github.com/CycloneDX/cdxgen
- Trivy documentation, SBOMTrivytrivy.dev/docs/latest/supply-chain/sbom/
- SBOM Toolmicrosoft/sbom-tool (GitHub)github.com/microsoft/sbom-tool
- CycloneDX CLICycloneDX/cyclonedx-cli (GitHub)github.com/CycloneDX/cyclonedx-cli
- SPDX tools-pythonSPDX (GitHub)github.com/spdx/tools-python
- NTIA Conformance CheckerSPDX (GitHub)github.com/spdx/ntia-conformance-checker
- protobom, format-neutral SBOM representationOpenSSF / protobom (GitHub)github.com/protobom/protobom
- sbomqs, SBOM quality score and compliance checkssbomqs (GitHub)github.com/interlynk-io/sbomqs
- sbom-scorecardeBay (GitHub)github.com/eBay/sbom-scorecard
- Grype, vulnerability scanner for container images, filesystems and SBOMsanchore/grype (GitHub)github.com/anchore/grype
- Trivy documentation, SBOM as a scan targetTrivytrivy.dev/docs/latest/target/sbom/
- OSV-Scannergoogle/osv-scanner (GitHub)github.com/google/osv-scanner
- OWASP Dependency-Track documentationOWASP Dependency-Trackdocs.dependencytrack.org/
- GUAC, Graph for Understanding Artifact CompositionOpenSSF / guacsec (GitHub)github.com/guacsec/guac
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.