Free tool
SBOM check
Open a CycloneDX or SPDX file to see what your SBOM is missing and which components have known vulnerabilities. The file is read in your browser and is not uploaded.
The file is read in your browser. Nothing is uploaded, and nothing leaves your browser until you start the vulnerability check below.
How the check works
- 01
Your file stays in your browser
The SBOM is read and checked on your device. Only when you start the vulnerability check are package identifiers sent, and only to OSV.dev. The product name, suppliers, hashes and everything else stay with you.
- 02
Good coverage for open-source packages
Components with a package URL (npm, PyPI, Maven, Go, Cargo, NuGet, Debian, Alpine and others) are looked up. Embedded libraries without a package URL are listed as not checked rather than shown as clean.
- 03
A starting point, not a verdict
Advisories say which versions are affected, not whether your product is exploitable. Use the results to prioritise, then confirm or rule out each case and record the decision.
Get in touch
Work out what the CRA actually asks of your product
Send us the product category and target markets. We will map the likely CRA class, the conformity assessment route that follows from it, and where the Annex I obligations will bite hardest for what you build.
We reply within two working days.
Full contact detailsOpens our scheduling page in a new tab — pick a slot that suits you.
Worth including in a first message
- What the product is, and whether it contains software or connects to a network.
- Which markets you sell into, and your role — manufacturer, importer, or distributor.
- Whether the product is already on the market or not yet released.
Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.