About
The SBOMApp tool brings comprehensive software supply chain security directly into VS Code. Developers can leverage natural language prompts to generate complete Software Bills of Materials (SPDX/CycloneDX) for their projects, including transitive dependencies. It provides deep insights by scanning for CVEs, detailing vulnerability information, and offering actionable fix versions and upgrade paths. Additionally, SBOMApp helps identify risky open-source licenses early, ensuring compliance. Designed for security-minded engineering organizations, it supports end-to-end visibility from local workspaces to builds and releases, all while guaranteeing absolute privacy by not storing user code or project data.