From Build Inventory to a Defensible Vulnerability Decision
SBOMator’s core workflow turns a repository, container, or firmware image into a standards-compliant SBOM, correlates it against multiple vulnerability sources, and preserves every engineering decision as machine- and human-readable evidence.
Accurate, Standards-Compliant SBOMs
CycloneDX 1.6 JSON and SPDX with direct and transitive dependencies, PURLs, versions, suppliers, licenses, hashes, and dependency relationships โ with automatic project detection.
CycloneDX 1.6 & SPDX
Industry-standard output with NTIA minimum-element support that imports cleanly into Dependency-Track and other consumers.
Direct & Transitive
Complete dependency trees with relationships, scoped to runtime, development, or complete as your evidence requires.
Fail-Closed Quality Gate
Unresolved versions or licenses are flagged with auditable exceptions โ an incomplete BOM never passes silently.
Comprehensive Mode
Merges Syft, CDXgen, and ecosystem-specific parsers into one deduplicated, reconciled inventory.
Suppliers & Licenses
Supplier/manufacturer enrichment, SPDX license normalization, and compound/dual-license expression preservation.
Scope & Exclusions
Inventory-only mode without CVE analysis, plus exclusions for test, CI, build, or vendored manifests.
15+ Languages & Ecosystems
From modern JavaScript monorepos to C/C++ build systems, containers, and Linux distributions.
Vulnerability Intelligence That Supports a Decision
Multiple sources combined with exploitation, reachability, lifecycle, and supplier evidence โ then preserved in machine- and human-readable form.
Version-aware matching
Ecosystem-aware CPE/CVE matching reduces cross-ecosystem false positives; backport, fixed-version, and affected-range filtering.
Exploitation context
CISA KEV known-exploited status and FIRST EPSS probability order remediation; weaponized and ransomware-linked CVEs identified.
CVSS v4.0 & v3.x
Parses, scores, and maps severity from both standards, with mixed v3/v4 CycloneDX ratings.
Coverage classification
Every component is marked matched, scanned clean, or not analyzed โ with disputed-CVE annotations.
VEX: Document Every Vulnerability State
CycloneDX VEX turns raw findings into defensible engineering dispositions with justifications and reachability.
Affected
Confirmed exposure with remediation detail and mitigation timeline.
Not Affected
Justification plus reachability and component-scope rationale.
Under Investigation
In-triage state carried forward across future scans.
Resolved
Fixed and preserved as part of the audit history.
Dashboard & Droid-as-Judge
The PyQt6 desktop dashboard loads CycloneDX JSON or HTML reports, turning component and CVE evidence into an interactive triage workspace โ with AI-assisted judging in an embedded terminal.
Select CVEs
Filter by severity, license, secrets, VEX state, and Ransomware / Weaponized / Standard threat class.
Send to Droid
Analyze checked CVEs with the Droid CLI running inside the dashboard’s real embedded terminal.
Judge & Justify
False positive, not affected, reachability, and the smallest safe fix โ explained with evidence.
VEX Evidence
Preserve the engineering decision and justification; diff two reports to track fix progress.
--auto medium and --disabled-tools Edit: it can read and create files but cannot modify existing files. It judges false positives and not-affected cases, explains reachability, and proposes the smallest safe fix or VEX justification. Factory and Droid are marks of Factory AI; no partnership or endorsement is implied.
Run the Full Scan-to-Decision Flow
Point SBOMator at a repository, container, or firmware image and get a standards-compliant SBOM, correlated vulnerabilities, and defensible VEX evidence โ entirely on-premises.