BOMHort

Ingest thousands of SPDX and CycloneDX SBOMs, scan for vulnerabilities via OSV, enforce license compliance, and apply VEX statements — all visualized in a fast Angular dashboard backed by ClickHouse analytics.

High Performance

ClickHouse MergeTree tables handle millions of dependency records. Virtual scrolling and OnPush change detection keep the UI responsive.

Vulnerability Intelligence

Automatic OSV API lookups for every package URL. Daily CVE Refresher finds newly disclosed vulnerabilities without re-scanning.

License Governance

Externalized license policy and exceptions. CNCF Allowed Third-Party License Policy enforced out of the box.

S3 Ingestion

Stream SBOMs from any S3-compatible bucket — AWS, MinIO, GCS, Oracle Cloud. No PVCs, no git-sync, scales to any repo size.

Multi-Format Support

SPDX 2.3, CycloneDX 1.0–1.7, and in-toto attestation envelopes — all auto-detected. Optional protobom backend for maximum format coverage.

Cloud Native

Helm chart with 19 templates. ClickHouse Operator for stateful lifecycle. Docker Compose for local development.