SBOMHub is an open-source dashboard that helps you manage Software Bill of Materials (SBOMs) and track vulnerabilities across all your projects. Import SBOMs from Syft, Trivy, or cdxgen. Get matched against NVD vulnerabilities. Prioritize by EPSS scores. Search CVEs across all projects instantly. Free tier available. Self-host option with AGPL-3.0 license.
Hey Product Hunt! š
I'm the maker of SBOMHub. Here's why I built it:
Generating SBOMs is easy (Syft, Trivy, etc.). Managing them is hard.
When Log4j happened, many teams couldn't quickly answer "are we affected?" because SBOMs were scattered across repos with no central view.
SBOMHub solves this:
ā Central dashboard for all project SBOMs
ā Automatic CVE matching from NVD
ā Cross-project search ("which repos use lodash < 4.17.21?")
ā EPSS scores to prioritize real risks
ā CLI for CI/CD integration
It's open-source (AGPL-3.0) and you can self-host for free, or use the cloud version.
Would love your feedback! What features would make this useful for your workflow?
Report
No reviews yetBe the first to leave a review for SBOMHub