Fetch the SPDX licence identifier for an open source package version to verify licence compatibility before adding a dependency. Supports PyPI, npm, Maven, Go, Cargo, NuGet, and RubyGems.
Enables searching, comparing, and validating SPDX licenses and exceptions, plus SPDX expression validation and SBOM analysis through a Streamable HTTP endpoint.
Register an SBOM once and continuously check for new CVEs affecting your dependencies. Supports CycloneDX and SPDX formats, returning new findings on each check.
Audit licence compatibility across your dependency list. Submit package names or SPDX IDs to receive a COMPATIBLE/CONFLICT verdict with conflicting pairs and recommended action.
Scan a project directory with Syft to generate a Software Bill of Materials (SBOM). Get an inventory of all software components and dependencies for compliance and vulnerability scanning.