BOMHort
Ingest thousands of SPDX and CycloneDX SBOMs, scan for vulnerabilities via OSV, enforce license compliance, and apply VEX statements — all visualized in a fast Angular dashboard backed by ClickHouse analytics.
High Performance
ClickHouse MergeTree tables handle millions of dependency records. Virtual scrolling and OnPush change detection keep the UI responsive.
Vulnerability Intelligence
Automatic OSV API lookups for every package URL. Daily CVE Refresher finds newly disclosed vulnerabilities without re-scanning.
License Governance
Externalized license policy and exceptions. CNCF Allowed Third-Party License Policy enforced out of the box.
S3 Ingestion
Stream SBOMs from any S3-compatible bucket — AWS, MinIO, GCS, Oracle Cloud. No PVCs, no git-sync, scales to any repo size.
Multi-Format Support
SPDX 2.3, CycloneDX 1.0–1.7, and in-toto attestation envelopes — all auto-detected. Optional protobom backend for maximum format coverage.
Cloud Native
Helm chart with 19 templates. ClickHouse Operator for stateful lifecycle. Docker Compose for local development.