Dependency & SBOM Visibility
Knowing exactly what components ship inside your software — direct and transitive — and being able to query that inventory when something changes.
5 OpenSSF projects and publications help with Visibility, each with a one-sentence note on how. Prefer another way in? Browse by role →
Bomctl
Bridges SBOM generation and analysis by fetching, merging, and translating bills of materials into one queryable inventory.
Full breakdown
GUAC
Aggregates SBOMs and attestations into one queryable graph so you can trace any component and its relationships.
Full breakdown
Protobom / SBOM Tools
Generates and translates SBOMs in standard formats so the component inventory travels with the artefact.
Full breakdown
SBOMit
Produces a standard SBOM as the carrier for that provenance, keeping the component inventory and its evidence together.
Full breakdown
Security Insights
Surfaces a project's vulnerability-handling process and resources so downstream consumers can reason about it programmatically.
Full breakdown