Free SBOM quality checks

Check the SBOM before it becomes product evidence.

Inspect CycloneDX JSON/XML and SPDX JSON/tag-value locally in your browser. The checker reports structure, component identity, metadata and dependency graph signals; it does not make a legal compliance determination.

Inspect a machine-readable SBOM

CycloneDX JSON/XML or SPDX JSON/tag-value · up to 5 MB · processed in this browser

or paste SBOM text

The file stays in this tab; Vellaci does not receive or store it.

Quality report

Your results will appear here.

Structure checks and useful matching signals help you decide what to improve before a release. These are operational observations, not a CRA compliance score.

Standards and workflow

Check identifiers, then keep the inventory with its release.

A package URL (purl), such as pkg:npm/express@4.18.2, gives a component a structured package identity that can improve advisory matching. The Package URL specification defines the syntax; CycloneDX and SPDX can carry purls in their component records.

Example purl: pkg:npm/express@4.18.2 identifies the npm package express at version 4.18.2. Read the concise Package URL definition. A purl is an identifier, not a guarantee that a package is safe or that an SBOM is complete.

Read the Package URL specification, the CycloneDX specification or SPDX 2.3. For automated release ingestion, see SBOM in CI/CD. After validation, Vellaci attaches each SBOM to a product version, preserves the original, matches components to vulnerability intelligence and records human triage and VEX decisions.