OpenSSF project

Protobom / SBOM Tools

A shared library and toolset for generating, translating, and consuming Software Bills of Materials in standard formats such as SPDX and CycloneDX.

How each persona uses Protobom / SBOM Tools

Software Developer / Maintainer Developer

Integrates SBOM generation tools into their local build process to automatically document the components used in their software.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Mandates the use of standard SBOM formats and tools like Protobom to maintain a comprehensive inventory of third-party software assets.

See everything for OSPO →

Security Engineer / Architect Security

Analyzes ingested SBOMs to rapidly identify and triage vulnerable components across the organization's application portfolio.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Embeds Protobom into the automated release pipeline to seamlessly generate and attach SBOMs to every compiled artifact.

See everything for DevOps →

Package & Repository Manager Package Manager

Distributes generated Software Bill of Materials (SBOMs) alongside packages to provide consumers with a transparent component inventory.

See everything for Package Manager →

Executive / End-User Consumer Executive

Demands SBOMs as trust signals to assess post-release risk and make informed consumption decisions.

See everything for Executive →

Problems Protobom / SBOM Tools helps with

Dependency & SBOM Visibility Visibility

Generates and translates SBOMs in standard formats so the component inventory travels with the artefact.

See everything for Visibility →