Drop in the software bill of materials for your product. It checks the 21 data fields CERT-In’s SBOM guidelines ask for, flags components attackers are known to use, licences that need a look, and duplicates, then says what to fix first. Read in your browser.
Or paste the SBOM
The file never leaves this browser
CycloneDX and SPDX, in JSON
Try it offline: it still works
Example report
order-portal 3.4.0 · CycloneDX
6 of 21 fields
A component attackers are using!
Supplier missing for half!
No VEX information●
More in the full report●●●
Reading the SBOM in your browser
Checking CERT-In’s 21 fields
Checking components against the list
Checking licences and duplicates
SBOM check
1 Summary
CERT-In’s 21 fields
2 The checks
3 What this could not check
Fields checked against CERT-In’s Technical Guidelines on SBOM (version 2.0), Table 5. Read in your browser; the file was never sent to us. Guidance, not an audit or a vulnerability scan; see the terms.
HOW TO GET ONE
Make an SBOM
An SBOM is generated from the code or the built image, not written by hand. Free, open-source generators do it in one command.
Use your build tool’s CycloneDX pluginMaven, Gradle, npm, pip and .NET all have one. It reads the exact versions the build resolved.
Ask for JSONCycloneDX 1.4 or later, or SPDX 2.3. XML and tag-value are not read here.
Drop the file inUsually named bom.json or sbom.json, in the build’s output folder.
Run an open-source SBOM generator on the imagePoint it at the image you ship, so the operating system packages are included too.
Choose CycloneDX JSON or SPDX JSON as the outputSave it to a file.
Drop the file inImage SBOMs can list hundreds of components; that is normal.
Ask the supplier for the SBOMCERT-In’s guidelines expect suppliers to provide one with the software, and to update it with each release.
Ask for machine-readable JSONA PDF or spreadsheet list is not an SBOM anyone can match against vulnerabilities.
Drop it inThe report shows which of the 21 fields they left out: a ready list to send back.
What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, and our copy of your details carries only the format and the counts, never a component name.
QUESTIONS
Asked often
The questions people search for before they run the check.
What is an SBOM?
A software bill of materials: a machine-readable list of every component inside a piece of software, with its version, supplier, licence and a unique identifier. It lets anyone check, in minutes, whether a newly announced flaw such as Log4Shell affects the software.
What does CERT-In require in an SBOM?
CERT-In's Technical Guidelines on SBOM (version 2.0, July 2025) list 21 minimum data fields, among them component name, version, supplier, licence, origin, dependencies, vulnerabilities, patch status, end-of-life date, hashes, the author and timestamp, and a unique identifier. This check shows how many of them your SBOM fills.
Which SBOM formats does this read?
CycloneDX and SPDX, in JSON, the two formats CERT-In's guidelines name. If your generator writes XML or SPDX tag-value, ask it for JSON instead; most can.
Is this a vulnerability scan?
No. It flags a short, dated list of notorious components, such as old Log4j, Spring and OpenSSL versions, but a full check needs a vulnerability scanner fed with the SBOM. This check is about whether the SBOM is complete enough for that scanner, and for CERT-In.
Is my SBOM uploaded?
No. It is read in your browser and dropped once the report is drawn. If you ask for the report, we keep your details and a one-line summary with the format and the counts, never a component name.
Godwit AI Labs
This report is available as a branded PDF. Use “Download the report” on the page,
or ask us for the detailed report at godwit-tech.com/contact.
Know what is inside what you ship
An SBOM generated with every release, the fields customers and regulators ask for, and vulnerability scanning fed from it, so the next Log4Shell is a search, not a scramble.