Skip to main content
Glama

endoflife.ai — Software Lifecycle Intelligence

Check an SBOM

check_sbom
Read-onlyIdempotent

Audit a CycloneDX or SPDX JSON software bill of materials. Components are mapped to tracked products and scored for EOL risk; unmatched components are listed honestly rather than guessed. Pass the SBOM as a JSON string or object. Versions resolve to their release family (python 3.12, php 7.4, ubuntu 20.04). Without a key up to 5 matched components are scored per call; Starter 25; Pro 50. Larger SBOMs return the scored subset plus a note of how many were not checked.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sbomYesThe SBOM document (JSON string or object). CycloneDX (bomFormat/components) or SPDX (spdxVersion/packages).
max_itemsNoOptional: return at most this many scored components (the tier cap applies first).

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedInput schema / properties / max_items / description
      Previous value: -"Maximum matched components to score (default 50)."New value: +"Optional: return at most this many scored components (the tier cap applies first)."
  2. First observed

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.