๐ก๏ธ
BOM Workbench
Give BOM Workbench either a BOM to inspect, validate, and compare, or a project folder to discover software configuration and generate a CycloneDX 1.7 BOM automatically.
๐ All analysis runs 100% locally in your browser. No source files or BOMs are ever uploaded.
BOM Summary & Metrics
Format & Spec
-
CycloneDX Schema
Components
0
Total cataloged
Relationships
0
Dependency links
With Hashes
0%
0 components
With Licenses
0%
0 components
With PURLs
0%
0 components
๐ฏ Root Component
| Name: | - |
| Version: | - |
| Type & Group: | - |
| PURL: | - |
| Description: | - |
๐ Document Metadata
| Serial Number: | - |
| BOM Version: | - |
| Timestamp: | - |
| Supplier / Org: | - |
| Authors / Tools: | - |
๐
Showing 0 components
| Name | Version | Type | Supplier | PURL | Licenses | Hashes |
|---|
Visualization:
๐
Focus: -
Depth:
Direction:
Group By:
Physics:
Scope:
โน Disclaimer
0 components ยท 0 relationships
Advanced Physics Parameters
๐ก
Large dependency graph detected. Focus / Neighborhood view is recommended for readability.
Root
Selected / Focus
Upstream (Dependents)
Downstream (Dependencies)
-
0 Upstream
0 Downstream
library
-
-
| Component | Depends On | Relationship Type | Action |
|---|
Live working copy: workspace.document
BOM Configuration Compare
Select two CycloneDX BOMs to see what changed in components, versions, dependencies, hashes, and licenses.
๐
BOM A (Baseline)
No file selected
๐
BOM B (Target / New)
No file selected
A: -
โ
B: -
+ 0 Added
- 0 Removed
ฮ 0 Changed
= 0 Unchanged
๐
| Status | Component | Old Version (A) | New Version (B) | Changed Fields | Match Method |
|---|
Added (+)
Removed (-)
Changed (ฮ)
Unchanged (=)
| Status | Component (From) | Depends On (To) |
|---|
๐ Document Metadata Differences
| Property | BOM A (Baseline) | BOM B (Target) |
|---|
BOM A JSON (Baseline)
BOM B JSON (Target)
Create BOM from Project Folder
Select a local project folder containing HTML, CSS, JavaScript, Dart, or Go source code to automatically discover components, packages, relationships, and generate a CycloneDX 1.7 BOM.
๐
Local Multi-Language Source Analysis
Recursively scans files, computes SHA-256 hashes, extracts package dependencies and source-level imports, and merges evidence without uploading any code.
๐ Browser-only static analysis. No code execution, no network calls.
๐ project-folder
Files Scanned
0
0 hashed
Components
0
Packages/Modules
Relationships
0
Source & deps
Evidence Records
0
Traceable lines
Unresolved
0
Unknown assets
๐ DEPENDENCY EVIDENCE:
Declared: 0
Referenced: 0
Resolved: 0
Fully Corroborated: 0
Declared Only: 0
Referenced Only: 0
Unresolved: 0
๐
| File Path | Language / Type | Size | SHA-256 Digest |
|---|
Scope & Status:
| Component Name | Version | Scope | Ecosystem | Evidence Status | Package URL (PURL) | Sources | Confidence |
|---|
Relationship Filter:
| Semantic Type | Source (From) | Target (To) | Analyzer | Confidence | Evidence |
|---|
| Source File | Line | Type | Analyzer | Claim / Excerpt |
|---|
Graph View:
Filter Edges:
๐๏ธ Project
๐ Manifest
๐ Lockfile
๐ Source File
๐ฆ Package
โ ๏ธ Unresolved