OSS Semantic SBOM diff and TUI analysis tool. Compares CycloneDX/SPDX files to component changes, dependency shifts, license conflicts, and vulnerabilities.

CI/CD Build Pipelines
sbom.tools is officially live🚀
4
23
107
16,562
SBOM-Tools retweeted
Unfortunately, the complexity of the hardware and firmware supply chain has the same negative effect on how cryptographic artifacts are managed, or mismanaged, across the ecosystem. This is a reminder of the scale of the problem, based on just one documented data breach.
⛓️Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem. It appears that Intel BootGuard may not be effective on certain devices based on the 11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake. Our investigation is ongoing, stay tuned for updates.
3
16
68
9,947
SBOM-Tools retweeted
Side-by-Side diff in TUI mode: sbom-tools diff tests/fixtures/demo-old.cdx.json tests/fixtures/demo-new.cdx.json
1
6
81
SBOM-Tools retweeted
I'm not sure open letters are an effective tool, but in this case we need every tool we can get to raise awareness of the point we've reached: we have neglected defense and accelerated offense with AI. All the security concepts and patterns the industry has used and adopted over the years in product security are becoming wrong assumptions. One pattern every vendor follows is raising the bar for an attacker with new mitigations or new layers of obscurity to win time, letting complexity become a security boundary. These old patterns are broken. The data shows they were never very effective against experienced attackers, and now we have an experienced attacker that can be scaled with unprecedented velocity, so winning time is a losing strategy by design. Defenders today don't have time, but we still have an opportunity to change the rules of the game.
10
8
44
6,278
SBOM-Tools retweeted
sbom-tools v0.2.0 is live 🚀 - AIBOM support improvements - multi-diff CLI for comparing the entire fleet - 16 compliance standards (+CISA 2026, PCI DSS, FSCT) - CDXA attestation ingestion - SPDX 3.0.1 JSON-LD parsing - sbomqs-compatible scoring output github.com/sbom-tool/sbom-to…
6
16
1,425
SBOM-Tools retweeted
Beyond the powerful TUI, CLI mode packs plenty of little gems for automating analysis and reporting. Side-by-Side diff in CLI mode: sbom-tools diff tests/fixtures/demo-old.cdx.json tests/fixtures/demo-new.cdx.json -o side-by-side
1
5
10
1,157
SBOM-Tools retweeted
Defining and standardizing a minimum valuable SBOM makes a lot of sense. Many vendors produce or provide SBOMs just to tick the compliance boxes, and those are completely useless for software supply chain analysis and monitoring. CISA just refreshed the SBOM Minimum Elements: SBOM: author, signature, format name/version, gen context, timestamp, tool name/version, version Component: producer, name, version, IDs, hash + algo, license, dependencies Coverage = all transitive deps.
Our 2026 Minimum Elements for a Software Bill of Materials (SBOM) helps organizations improve supply chain transparency & risk management. Check out the updated guidance to learn more about new data fields, practices & processes 🔗 go.dhs.gov/5ms
3
11
534
Beyond the powerful TUI, CLI mode packs plenty of little gems for automating analysis and reporting. Side-by-Side diff in CLI mode: sbom-tools diff tests/fixtures/demo-old.cdx.json tests/fixtures/demo-new.cdx.json -o side-by-side
1
5
10
1,157
Side-by-Side diff in TUI mode: sbom-tools diff tests/fixtures/demo-old.cdx.json tests/fixtures/demo-new.cdx.json
1
6
81
SBOM-Tools retweeted
I'm excited about NIST SP 800-239, "AI Data Center Security Analysis." It's solid threat coverage and gap analysis, and honestly useful for any modern data center, not just AI ones. I hope it leads to deeper industry-wide conversations on this topic. My main concern is that there aren't many actual controls, and FW/HW threats remain one of the biggest gaps, as they always have been. The attack vectors discussed in SP 800-239 aren't new, but beyond integrity checks, event logging, and general defense-in-depth practices, there still isn't much that can be controlled at that layer. It feels like this needs a push for more visibility and transparency across the entire ecosystem. The attack vectors we face today are decades old when it comes to supply chain, UEFI, or BMC threats. What's changed is the complexity of modern servers, which has increased significantly.
📢@NIST invites public comments on the initial public draft of SP 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach, which examines the security landscape of artificial intelligence (AI) data centers. Learn more: csrc.nist.gov/pubs/sp/800/23…
5
23
3,772
🚀SBOM.Tools v0.1.22: the AI BOM release! Parses CycloneDX ML-BOMs & SPDX 3.0 AI/Dataset, scores AI-readiness, and machine-checks the EU AI Act + G7/BSI. - semantic ML model & dataset diffing - offline/air-gapped mode + cache management - model-weight integrity & Hugging Face enrichment - CISA KEV & EPSS enrichment and more... github.com/sbom-tool/sbom-to…
1
5
11
1,165
SBOM-Tools retweeted
sbom-tools v0.1.21 is out 🩹Bug-fix release: - view -o json: full vuln detail + dependency_kind - diff similarity: bounded 0–100 - CRA section in diff reports: compact summary Thanks @MCh0rfa for all three fixes👏 cargo | brew install sbom-tools github.com/sbom-tool/sbom-to…
3
9
1,379
SBOM-Tools retweeted
Shipped SBOM.Tools v0.1.20 🚀 This one's all about EU Cyber Resilience Act (CRA) readiness. - New cra-docs command, generates your Annex V Declaration of Conformity straight from the SBOM - Full CSAF v2.0 round-trip - Article 24 OSS steward profile for maintainers - CRA standards-drift detection in `watch` - 14 compliance levels now, including CNSA 2.0 and NIST PQC If you're staring down CRA deadlines, this should make life easier. github.com/sbom-tool/sbom-to…
9
26
3,005
SBOM-Tools retweeted
🔐sbom-tools v0.1.19 ships a CBOM quality engine that actually grades it: - Algorithm strength + PQC readiness - OID & metadata coverage - Key/cert lifecycle hygiene sbom-tools quality --profile cbom github.com/sbom-tool/sbom-to…
8
15
2,778
SBOM-Tools retweeted
Lately I've been thinking about how AI is changing vulnerability research and reverse engineering. VR and RE are some of the hardest workflows to parallelize. Even with great knowledge transfer and team practices, you usually default to one person per vuln or RE task. The work is just too context-heavy to split. AI breaks that ceiling. It's no longer "one researcher, one task", it's you working one angle while Claude annotates disassembly code, explores another path, or helps you piece together what the last result means. Watching this land in domains we assumed were fundamentally serial is wild.
12
53
278
35,601