OpenSSF project
Bomctl
Format-agnostic Software Bill of Materials tooling that bridges the gap between SBOM generation and SBOM analysis — fetching, merging, and manipulating SBOMs across SPDX and CycloneDX.
How each persona uses Bomctl
Software Developer / Maintainer Developer
Fetches and merges the SBOMs for their project's dependencies into a single document they can inspect and hand downstream.
Open Source Professional (OSPO) OSPO
Normalizes SBOMs arriving in mixed formats into a consistent inventory the organization can track across every project.
Security Engineer / Architect Security
Pulls together SBOMs from disparate sources so a component can be traced wherever it appears in the portfolio.
CI/CD DevOps & Tooling Integrator DevOps
Wires bomctl into the pipeline to fetch, merge, and reformat SBOMs as a build step rather than a manual chore.
Package & Repository Manager Package Manager
Translates and consolidates incoming SBOMs so the registry can serve a clean, format-consistent component inventory.
Problems Bomctl helps with
Dependency & SBOM Visibility Visibility
Bridges SBOM generation and analysis by fetching, merging, and translating bills of materials into one queryable inventory.