Godwit AI Labs Talk to us

Home › Free tools › SBOM check

Does your SBOM meet CERT-In’s list?

Drop in the software bill of materials for your product. It checks the 21 data fields CERT-In’s SBOM guidelines ask for, flags components attackers are known to use, licences that need a look, and duplicates, then says what to fix first. Read in your browser.

Or paste the SBOM
  • The file never leaves this browser
  • CycloneDX and SPDX, in JSON
  • Try it offline: it still works
HOW TO GET ONE

Make an SBOM

An SBOM is generated from the code or the built image, not written by hand. Free, open-source generators do it in one command.

  1. Use your build tool’s CycloneDX pluginMaven, Gradle, npm, pip and .NET all have one. It reads the exact versions the build resolved.
  2. Ask for JSONCycloneDX 1.4 or later, or SPDX 2.3. XML and tag-value are not read here.
  3. Drop the file inUsually named bom.json or sbom.json, in the build’s output folder.

What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, and our copy of your details carries only the format and the counts, never a component name.

QUESTIONS

Asked often

The questions people search for before they run the check.

What is an SBOM?

A software bill of materials: a machine-readable list of every component inside a piece of software, with its version, supplier, licence and a unique identifier. It lets anyone check, in minutes, whether a newly announced flaw such as Log4Shell affects the software.

What does CERT-In require in an SBOM?

CERT-In's Technical Guidelines on SBOM (version 2.0, July 2025) list 21 minimum data fields, among them component name, version, supplier, licence, origin, dependencies, vulnerabilities, patch status, end-of-life date, hashes, the author and timestamp, and a unique identifier. This check shows how many of them your SBOM fills.

Which SBOM formats does this read?

CycloneDX and SPDX, in JSON, the two formats CERT-In's guidelines name. If your generator writes XML or SPDX tag-value, ask it for JSON instead; most can.

Is this a vulnerability scan?

No. It flags a short, dated list of notorious components, such as old Log4j, Spring and OpenSSL versions, but a full check needs a vulnerability scanner fed with the SBOM. This check is about whether the SBOM is complete enough for that scanner, and for CERT-In.

Is my SBOM uploaded?

No. It is read in your browser and dropped once the report is drawn. If you ask for the report, we keep your details and a one-line summary with the format and the counts, never a component name.

Know what is inside what you ship

An SBOM generated with every release, the fields customers and regulators ask for, and vulnerability scanning fed from it, so the next Log4Shell is a search, not a scramble.