Introduction
This site generates SPDX, SWID and CycloneDX format SBOMs from user provided data.
Fields with dashed border are optional.
SPDX-Lite fields are supported. This is in support of
Healthcare PoC (Proof of Concept) II efforts from
NTIA in collaboration with a number of
organizations.
Usage Instructions
- Watch quick introduction videos playlist
@ YouTube
- Click on top right corner CERT icon to toggle "Dark Mode" on and off
- Click on "Load Example" for simple view of a
SPDX lite loaded into three formats (SPDX, SWID and CycloneDX)
as well as a simple SVG graph representation of the Components and their
relationship
- SPDX Lite fields are supported, click on the "SPDX Lite" button to
activate it. SPDX Lite fields are set to default values when NOT in use.
- You can import SPDX in text format (RDFa) and Excel sheet in conformance to
Template are supported as inputs.
- When loading Excel file, use the template as provided. DO NOT delete the
top header rows OR rename the sheets. Edit only the fields relevant
for your product which is to be documented in SBOM formats.
- Excel file does not support specifying relationships. The template builds
a flat tree which you can later modify once data is laoded. Once you have
generated SPDX, you can import it again using the SPDX file to maintain
relationships and do edits/modification to your product SBOM.
- The github repo is provided in the link on the top right corner. Fork and use
it as you please. We only ask that you credit
CERT when publishing this software in an Intranet or external Internet.
-
In Graph mode, you can click on Vulnerabilities to edit - add or remove vulnerbailities per foand remove all the vulnerabilities using the "-" minus sign and then click Simulate to see plain graph no vulnerability simulated and no red dots.
-
If you have trouble using this software or desire a feature, please reach out
using Github's "Issues".
Privacy and Data Security
None of the data you enter or simulate is sent or stored at the server. The data is solely on the client-side. The tools to generate SPDX,SWID and CycloneDX can all work even if your browser is disconnected from the network after loading the website.