OpenSSF project

Bomctl

Format-agnostic Software Bill of Materials tooling that bridges the gap between SBOM generation and SBOM analysis — fetching, merging, and manipulating SBOMs across SPDX and CycloneDX.

How each persona uses Bomctl

Software Developer / Maintainer Developer

Fetches and merges the SBOMs for their project's dependencies into a single document they can inspect and hand downstream.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Normalizes SBOMs arriving in mixed formats into a consistent inventory the organization can track across every project.

See everything for OSPO →

Security Engineer / Architect Security

Pulls together SBOMs from disparate sources so a component can be traced wherever it appears in the portfolio.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Wires bomctl into the pipeline to fetch, merge, and reformat SBOMs as a build step rather than a manual chore.

See everything for DevOps →

Package & Repository Manager Package Manager

Translates and consolidates incoming SBOMs so the registry can serve a clean, format-consistent component inventory.

See everything for Package Manager →

Problems Bomctl helps with

Dependency & SBOM Visibility Visibility

Bridges SBOM generation and analysis by fetching, merging, and translating bills of materials into one queryable inventory.

See everything for Visibility →