| domain | sbom.sh |
| summary | The website showcases a Vulnerability Management Platform that automates the creation of Software Bill of Materials (SBOM) and vulnerability scanning, trusted by numerous organizations. It demonstrates this capability using three examples:
1. Trivy scan for a container image (Postgres), executed with the command `trivy --scanners vuln -q`. 2. Syft analysis for another container image (Docker PostgreSQL), performed via `syft registry:docker.iopostgres -o cyclonedx-json -q` and then parsed using `curl -d - https://sbom.sh -H Content-Type: application/json`. 3. Grype inspection for a third container image, conducted with the command `grype registry:docker.iopostgres -o cyclonedx-json -q` and processed similarly via `curl`.
Additionally, it illustrates using GitHub's dependency graph feature by executing two curl commands to fetch the SBOM from GitHub API endpoints. The first command uses a bearer token for authentication, while the second one sends an empty payload for SBOM data. |
| title | SBOM.sh - Your Trusted CycloneDX and SPDX Software Bill of Materials platform |
| description | SBOM provides comprehensive Software Bill of Materials (SBOM) solutions to enhance software supply chain security and compliance. Explore our services today. |
| keywords | vulnerability, container, image, scan, using, https, quality, generation, analysis, curl, repository, scoring, docker, name, share, integration, metrics |
| upstreams |
|
| downstreams |
|
| nslookup | A 176.9.102.218 |
| created | 2025-11-08 |
| updated | 2025-11-08 |
| summarized | 2025-11-12 |
|
|