Ross ROSS = Recommend OSS · open-source software intelligence for agents

microsoft/sbom-tool

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts. observed · 2026-08-28

github.com/microsoft/sbom-tool · C# · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

81/100

  • Activity 88
  • Release rhythm 61
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 27.0
  • age_days: 1554
  • days_rel: 261
  • days_push: 76
  • n_releases_24m: 13

Full methodology

Adoption not part of the score

2068 stars · 199 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Microsoft's SBOM Tool is a scalable, enterprise-ready CLI that generates SPDX 2.2 and SPDX 3.0 compatible Software Bill of Materials documents for a wide variety of build artifacts. It detects components using Microsoft's Component Detection libraries and enriches them with license information from the ClearlyDefined API.

Use cases

  • generate an SPDX SBOM for my build artifacts
  • create a software bill of materials in CI/CD pipelines
  • generate SBOMs for compliance and supply chain security
  • detect open source components and their licenses in a project
  • produce SPDX 2.2 SBOM files for enterprise release processes
  • scan a directory and output an SBOM manifest

When to choose

  • you need SPDX 2.2 or 3.0 compatible SBOM generation at enterprise scale
  • you want a maintained Microsoft tool with CI/CD integration and cross-platform binaries
  • you need automatic component detection with license enrichment

When to avoid

  • you need CycloneDX format output rather than SPDX
  • you need vulnerability scanning or SBOM validation rather than generation
  • you need a GUI-based SBOM workflow

Facets

cli-tool · maturity active

security developer-tools cli ci-cd security developer-tools windows cli cross-platform sbom spdx supply-chain-security component-detection license-scanning devops linux macos docker

1 source

Member repositories

RepositoryRoleHealth v2
microsoft/sbom-toolmain81

For agents

markdown · JSON · MCP: product_card(name="microsoft/sbom-tool")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem