Free SBOM quality checks
Check the SBOM before it becomes product evidence.
Inspect CycloneDX JSON/XML and SPDX JSON/tag-value locally in your browser. The checker reports structure, component identity, metadata and dependency graph signals; it does not make a legal compliance determination.
Inspect a machine-readable SBOM
CycloneDX JSON/XML or SPDX JSON/tag-value · up to 5 MB · processed in this browser
The file stays in this tab; Vellaci does not receive or store it.
Quality report
Your results will appear here.
Structure checks and useful matching signals help you decide what to improve before a release. These are operational observations, not a CRA compliance score.
Standards and workflow
Check identifiers, then keep the inventory with its release.
A package URL (purl), such as pkg:npm/express@4.18.2, gives a component a structured package identity that can improve advisory matching. The Package URL specification defines the syntax; CycloneDX and SPDX can carry purls in their component records.
Example purl: pkg:npm/express@4.18.2 identifies the npm package express at version 4.18.2. Read the concise Package URL definition. A purl is an identifier, not a guarantee that a package is safe or that an SBOM is complete.
Read the Package URL specification, the CycloneDX specification or SPDX 2.3. For automated release ingestion, see SBOM in CI/CD. After validation, Vellaci attaches each SBOM to a product version, preserves the original, matches components to vulnerability intelligence and records human triage and VEX decisions.
Read next
- Guide
SBOM guide for the CRA: formats, minimum content and operations
CycloneDX versus SPDX, what a CRA-oriented SBOM must contain, which tools generate one per ecosystem, how to keep it current per release, how to share it, and how it feeds vulnerability handling and VEX.
- Docs
SBOM ingestion
Upload, GitHub, GitLab, CI/CD and the API.
- Docs
CI/CD SBOM ingestion
GitHub Actions, GitLab CI, Jenkins, CircleCI examples.
- Docs
VEX
Per-product exploitability statements and signed CycloneDX VEX documents.