gcve-sbom-analyzer
PulseGate's liveness check found it on 29 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 29 Sep 2026. How this is checked
gcve-sbom-analyzer is an open-source command-line tool that cross-references components in CycloneDX and SPDX SBOMs with vulnerability databases. It is intended for developers and security teams performing software supply-chain security checks.
Inferred · not functionally tested
Overview
6 featuresPurpose: Identifying vulnerabilities in software components listed in SBOM files.
Inferred · not functionally tested
Audience: software security engineers and developers
Inferred · not functionally tested
Functions: data_extraction
Inferred · not functionally tested
Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)
Recorded constraints: pricing: open_source · license: GPL-3.0 · platforms: CLI · deployment: cli, self_hosted
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: pypi.org · github.com. These links do not verify the individual claims.
gcve-sbom-analyzer sits in PulseGate's Application security & vulnerability scanning category. Inferred · not functionally tested: It focuses on identifying vulnerabilities in software components listed in SBOM files. Inferred · not functionally tested: gcve-sbom-analyzer is an open-source project aimed at software security engineers and developers. Basis unknown · not verified: gcve-sbom-analyzer is open source under the GPL-3.0 license. Basis unknown · not verified: gcve-sbom-analyzer is available on the command line, and it can be self-hosted.
Samy Difallah builds and maintains gcve-sbom-analyzer, and it first shipped in 2026. The project is developed in the open on GitHub with 91 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include SBOM analysis, cycloneDX support, and SPDX support.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- SBOM analysis
- CycloneDX support
- SPDX support
- CVE lookup
- GCVE lookup
- OSV lookup
Topics: Inferred · not functionally tested
Built with & integrations
- Claude Code
- CLAUDE.md
Trust & compliance
Indexing history
3What PulseGate has recorded for this listing
- Indexed29 Sep · 22:53 UTCgcve-sbom-analyzer seen via PyPI Bulk EnumeratorSource: PyPI Bulk Enumerator · Open
Frequently asked questions about gcve-sbom-analyzer
- What is gcve-sbom-analyzer?
- Inferred · not functionally tested: Gcve-sbom-analyzer focuses on identifying vulnerabilities in software components listed in SBOM files. It is catalogued under Application security & vulnerability scanning on PulseGate.
- Who should use gcve-sbom-analyzer?
- Inferred · not functionally tested: gcve-sbom-analyzer is an open-source project built for software security engineers and developers.
- Is gcve-sbom-analyzer free?
- Basis unknown · not verified: Yes — gcve-sbom-analyzer is open source under the GPL-3.0 license and free to use.
- What platforms does gcve-sbom-analyzer run on?
- Basis unknown · not verified: gcve-sbom-analyzer runs on the command line. It can also be self-hosted.
- Is gcve-sbom-analyzer still maintained?
- PulseGate's liveness check found it on 29 Sep 2026. Its GitHub repository shows 91 commits in the last 90 days.
- Who develops gcve-sbom-analyzer?
- gcve-sbom-analyzer is developed by Samy Difallah.
- When did gcve-sbom-analyzer launch?
- gcve-sbom-analyzer first shipped in 2026.
- Is gcve-sbom-analyzer open source?
- Basis unknown · not verified: Yes — gcve-sbom-analyzer is open source under the GPL-3.0 license, developed on GitHub.
Similar projects
Closest matches by what these projects do