Skip to content
Back to the index

gcve-sbom-analyzer

PyPIInfrastructure

PulseGate's liveness check found it on 29 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 29 Sep 2026. How this is checked

gcve-sbom-analyzer is an open-source command-line tool that cross-references components in CycloneDX and SPDX SBOMs with vulnerability databases. It is intended for developers and security teams performing software supply-chain security checks.

Inferred · not functionally tested

Open SourceGPL-3.0CLISelf-hosted
Visit PyPI

Overview

6 features

Purpose: Identifying vulnerabilities in software components listed in SBOM files.

Inferred · not functionally tested

Audience: software security engineers and developers

Inferred · not functionally tested

Functions: data_extraction

Inferred · not functionally tested

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)

Recorded constraints: pricing: open_source · license: GPL-3.0 · platforms: CLI · deployment: cli, self_hosted

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org · github.com. These links do not verify the individual claims.

gcve-sbom-analyzer sits in PulseGate's Application security & vulnerability scanning category. Inferred · not functionally tested: It focuses on identifying vulnerabilities in software components listed in SBOM files. Inferred · not functionally tested: gcve-sbom-analyzer is an open-source project aimed at software security engineers and developers. Basis unknown · not verified: gcve-sbom-analyzer is open source under the GPL-3.0 license. Basis unknown · not verified: gcve-sbom-analyzer is available on the command line, and it can be self-hosted.

Samy Difallah builds and maintains gcve-sbom-analyzer, and it first shipped in 2026. The project is developed in the open on GitHub with 91 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include SBOM analysis, cycloneDX support, and SPDX support.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • SBOM analysis
  • CycloneDX support
  • SPDX support
  • CVE lookup
  • GCVE lookup
  • OSV lookup

Topics: Inferred · not functionally tested

Tags
sbom-analysisvulnerability-scanningsupply-chain-securitycve-detection

JSON profile · Text profile · Access guide

Built with & integrations

Written with
Claude Code
Runs on
CLISelf-hosted
Written with — evidence
Claude Code
CLAUDE.md

Trust & compliance

License
GPL-3.0
Public signals
HTTPSOpen SourceFree tierGitHubActive maintenance

Indexing history

3

What PulseGate has recorded for this listing

  1. Indexed5 Oct · 21:49 UTC
    gcve-sbom-analyzer seen via PyPI Fresh Feed
    Source: PyPI Fresh Feed · Open
  2. Indexed4 Oct · 11:23 UTC
    gcve-sbom-analyzer seen via PyPI Fresh Feed
    Source: PyPI Fresh Feed · Open
  3. Indexed29 Sep · 22:53 UTC
    gcve-sbom-analyzer seen via PyPI Bulk Enumerator
    Source: PyPI Bulk Enumerator · Open

Frequently asked questions about gcve-sbom-analyzer

What is gcve-sbom-analyzer?
Inferred · not functionally tested: Gcve-sbom-analyzer focuses on identifying vulnerabilities in software components listed in SBOM files. It is catalogued under Application security & vulnerability scanning on PulseGate.
Who should use gcve-sbom-analyzer?
Inferred · not functionally tested: gcve-sbom-analyzer is an open-source project built for software security engineers and developers.
Is gcve-sbom-analyzer free?
Basis unknown · not verified: Yes — gcve-sbom-analyzer is open source under the GPL-3.0 license and free to use.
What platforms does gcve-sbom-analyzer run on?
Basis unknown · not verified: gcve-sbom-analyzer runs on the command line. It can also be self-hosted.
Is gcve-sbom-analyzer still maintained?
PulseGate's liveness check found it on 29 Sep 2026. Its GitHub repository shows 91 commits in the last 90 days.
Who develops gcve-sbom-analyzer?
gcve-sbom-analyzer is developed by Samy Difallah.
When did gcve-sbom-analyzer launch?
gcve-sbom-analyzer first shipped in 2026.
Is gcve-sbom-analyzer open source?
Basis unknown · not verified: Yes — gcve-sbom-analyzer is open source under the GPL-3.0 license, developed on GitHub.

Similar projects

Closest matches by what these projects do