Tooling
The tools in this field fall into two families that do different jobs and are not substitutes. Confusing them is the most expensive mistake in the programme; the page Generate and steer explains why.
| Generators | Platforms | |
|---|---|---|
| Level | Application, one artefact | Organisation, the portfolio |
| Question | “What is inside this artefact?” | “Which of your products contain this component?” |
| Trigger | A build | A newly published vulnerability |
| Output | A CycloneDX or SPDX file | Dashboards, alerts, reports, API |
| Examples | Syft, Trivy, Grype, cdxgen, osv-scanner | OWASP Dependency-Track, Snyk, FOSSA, Black Duck |
How to read the profiles
Each tool is described against the same template: vendor, licence and business model, level, supported formats, ecosystem coverage, vulnerability sources, licence detection, VEX support, integrations, deployment mode and data sovereignty, strengths, limits, and a verdict for your context.
Caveat. These profiles describe categories of product and their structural properties, not a snapshot of the market: versions, pricing and coverage change. Any purchasing decision must rest on an evaluation run against your own artefacts, following the protocol in Selection criteria.
The position adopted
Two principles guide the target tooling:
- An open, standardised generator, so the SBOMs you produce stay portable and independent of whichever platform consumes them. A proprietary SBOM is a liability.
- A steering platform, starting with a self-hostable option to validate the processes at zero software cost, before deciding on a commercial product if scale or legal requirements justify it.
In this section
Cyber
SBOM generators
Application-level tools: Syft, Grype, Trivy, cdxgen, osv-scanner, ScanCode, OSS Review Toolkit and native build-chain plugins.
Cyber
Steering platforms
Organisation-level tools: OWASP Dependency-Track, Snyk, FOSSA, Black Duck, Mend, Sonatype, JFrog Xray, GUAC — and what really separates them.
Leadership
Selection criteria and evaluation protocol
A weighted grid, an evaluation protocol run against your own artefacts, and the recommended tooling architecture.