sbomify is a security artifact hub for teams that generate, manage, and share SBOMs and compliance documents with stakeholders. It is built around software supply-chain transparency, and the site describes it as a place where security artifacts can be created, managed, and shared so trust can move from vendor to buyer to auditor.
The product centers on SBOM generation in CI pipelines through an open source action. It says SBOMs are automatically uploaded to sbomify after generation, where releases can be managed, including complex hierarchies, and the latest software versions can be shared publicly or privately through a Trust Center. The Trust Center also supports sharing SBOMs, compliance documents, and other security artifacts in a standardized way, and it can be hosted on a custom domain. The page also mentions programmatic compliance documents and audit-ready evidence alongside SBOMs.
For engineers, sbomify says it supports generation in CI with GitHub, GitLab, Bitbucket, and 14 languages. For security teams, it offers branded trust center hosting for SOC 2, ISO 27001, and SBOMs side by side. For compliance use cases, it references CRA, EO 14028, and NTIA. The service integrates with GitHub, GitLab, Bitbucket, Docker, analysis tools including Google OSV and Dependency Track, and enrichment platforms such as Ecosyste.ms.
sbomify is available as a self-hosted option on GitHub and as a managed cloud service. The page says both options provide the same capabilities, including CycloneDX and SPDX support, and describes the product as vendor agnostic with no vendor lock-in. Pricing pages are linked from the site, and the page also offers Cloud Free and Self-Host options.
sbomify-action is a Security & compliance platforms project. It focuses on automating the creation and management of software bill of materials for improved supply chain security in CI/CD workflows. sbomify-action is an open-source project aimed at devops engineers and security teams. The project is open source (Apache-2.0). It runs on the web, the command line, and API.
sbomify-action first shipped in 2024. The project is developed in the open on GitHub with 25 stars and 300 commits in the last 90 days. Among its 8 catalogued features are SBOM generation, SBOM enrichment, and SBOM management.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do