sbomdrift is a Python tool that analyzes Software Bill of Materials (SBOM) files in CycloneDX or SPDX format to track how their vulnerability posture evolves over time. It identifies newly vulnerable components by comparing against prior scans using OSV data. Designed for supply-chain security workflows, it helps developers and security teams monitor drift in open-source dependencies.
In the Developer Tools space, sbomdrift takes a focused approach. It focuses on detecting and tracking how the vulnerability exposure of software bill of materials changes between scans. It is built as an open-source project for developers. The project is open source (Apache-2.0). sbomdrift is available on the command line.
Behind sbomdrift is EngineerSamet, and it first shipped in 2026. Development happens publicly on GitHub with 8 commits in the last 90 days. Key capabilities include SBOM vulnerability tracking, cycloneDX support, and SPDX support.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match