Deptic makes software supply chain security effortless. Connect your GitHub repo and we instantly generate compliant Software Bills of Materials (SBOMs) and detect critical CVEs across your dependencies. Stay NTIA and EU CRA compliant with zero friction. Supports npm, pip, Maven, Go. Free for developers!
No reviews yetBe the first to leave a review for Deptic
Hunter
📌
Hi Product Hunt! 👋 I'm Balasanjeev, the maker of Deptic.
Modern software is built on thousands of open-source dependencies, making the software supply chain a massive target for hackers. On top of that, new regulations like the US Executive Order 14028 (NTIA) and EU CRA now legally require companies to maintain a Software Bill of Materials (SBOM).
I built Deptic to completely automate this headache for developers.
Instead of wrestling with clunky CLI tools, Deptic connects directly to your GitHub repository. It automatically reads your manifests (package.json, go.mod, pom.xml, etc.), maps your entire dependency tree, and checks every single package against the global CVE vulnerability databases.
Key Features: 🛡️ Instant SBOMs: Export perfectly formatted CycloneDX (1.5) and SPDX (2.3) files. 🚨 CVE Detection: Automatically flags critical security flaws in your code. ✅ Compliance Scoring: Pass government requirements instantly. 💻 Broad Support: Works with npm, pip, Maven, Go.
It is completely free to start using right now. I would love to hear your feedback on the UI and the scanning speed, Bugs etc.., Let me know what you think in the comments! 👇