https://github.com/sktelecom/bomlens
BomLens — a local-first SBOM generator & open-source risk assessor (CycloneDX). Produce an SBOM, an open-source notice, and a security/license risk report from source code, containers, binaries, firmware, or an SBOM you received. CLI or web UI, no SaaS.
https://github.com/sktelecom/bomlens
cdxgen cyclonedx devsecops docker firmware-analysis license-compliance open-source-security sbom sbom-generator sca software-bill-of-materials supply-chain-security syft trivy vulnerability-scanning
Last synced: 1 day ago
JSON representation
BomLens — a local-first SBOM generator & open-source risk assessor (CycloneDX). Produce an SBOM, an open-source notice, and a security/license risk report from source code, containers, binaries, firmware, or an SBOM you received. CLI or web UI, no SaaS.
- Host: GitHub
- URL: https://github.com/sktelecom/bomlens
- Owner: sktelecom
- License: apache-2.0
- Created: 2026-02-14T07:24:44.000Z (5 months ago)
- Default Branch: main
- Last Pushed: 2026-07-21T03:05:13.000Z (2 days ago)
- Last Synced: 2026-07-21T03:07:45.811Z (2 days ago)
- Topics: cdxgen, cyclonedx, devsecops, docker, firmware-analysis, license-compliance, open-source-security, sbom, sbom-generator, sca, software-bill-of-materials, supply-chain-security, syft, trivy, vulnerability-scanning
- Language: Shell
- Homepage: https://sktelecom.github.io/bomlens/
- Size: 19.6 MB
- Stars: 10
- Watchers: 0
- Forks: 1
- Open Issues: 6
-
Metadata Files:
- Readme: README.md
- Changelog: CHANGELOG.md
- Contributing: CONTRIBUTING.en.md
- License: LICENSE
- Code of conduct: CODE_OF_CONDUCT.en.md
- Security: SECURITY.en.md
- Support: SUPPORT.md
- Notice: NOTICE
Awesome Lists containing this project
README
BomLens
> **BomLens** is a local-first [SBOM](https://sktelecom.github.io/bomlens/concepts/what-is-sbom/) generator and open-source risk assessor. It produces a CycloneDX SBOM, an open-source notice, and a security and license risk report for a single project in seconds — from source code, a container, a binary, firmware, an SBOM you received, or a HuggingFace AI model. CLI or browser UI, no SaaS.
[](https://github.com/sktelecom/bomlens/releases)
[](https://github.com/sktelecom/bomlens/pkgs/container/bomlens)
[](LICENSE)
[](https://www.bestpractices.dev/projects/13059)
[](https://securityscorecards.dev/viewer/?uri=github.com/sktelecom/bomlens)
## What it does
One Docker image, two jobs. It **generates**: scan your source code, a container image, or a binary and get a CycloneDX SBOM, an open-source notice, and a security report. It also **assesses open-source risk** in what you receive — a supplier's finished SBOM (`--analyze`) or a firmware binary — reporting licenses and known vulnerabilities with Critical-7d / High-30d remediation deadlines. Every scan emits the risk report by default. Originally built by SK Telecom for supply-chain security, now open source.
Languages: Java, Python, Node.js, Ruby, PHP, Rust, Go, .NET, Swift, C/C++ (Conan/vcpkg, or `--identify-vendored` when there is no package manager). Inputs: a source folder, a GitHub URL, a ZIP archive, a Docker image, a binary or RootFS, an existing SBOM, firmware, or a HuggingFace AI model (CycloneDX ML-BOM checked against the [G7 minimum elements for AI](https://sktelecom.github.io/bomlens/guides/ai-model/), which map to the EU AI Act's Annex IV).
Full docs — searchable, English and Korean — live at **[sktelecom.github.io/bomlens](https://sktelecom.github.io/bomlens/)**, mirrored under [docs/](docs/):
- [First scan](docs/start/first-scan.md) ([한국어](docs/start/first-scan.ko.md)) — install through your first SBOM
- [No-CLI quick start](docs/start/no-cli.md) ([한국어](docs/start/no-cli.ko.md)) — click by click, for non-developers
- [Input scenarios](docs/guides/by-input.md) — GitHub URL, ZIP, local source, an existing SBOM, firmware
- [CLI reference](docs/reference/cli.md) — every option and environment variable
- Contributing to the tool itself — [CONTRIBUTING](CONTRIBUTING.en.md) and the [architecture](docs/concepts/architecture.md)
## Quick Start
Everything runs on a Docker engine (20.10+). The desktop app and web UI manage the image for you; only the CLI asks you to pull it. On Windows, free [Rancher Desktop](https://rancherdesktop.io/) or WSL2 + docker-ce works well; Docker Desktop also works, with licensing caveats for larger organizations.
### Desktop app — no command line (recommended)
Download the installer and double-click it: [BomLens-Setup.exe](https://github.com/sktelecom/bomlens/releases/latest/download/BomLens-Setup.exe) for Windows or [BomLens-Setup.dmg](https://github.com/sktelecom/bomlens/releases/latest/download/BomLens-Setup.dmg) for macOS. It checks Docker, pulls the image, and opens the UI — no console window. The app is unsigned for now; if Windows SmartScreen or macOS blocks it, the [no-CLI quick start](docs/start/no-cli.md) ([한국어](docs/start/no-cli.ko.md)) shows how to proceed. Build details are in [`electron/`](electron/README.md).

### Web UI
```bash
git clone https://github.com/sktelecom/bomlens.git && cd bomlens
./scripts/scan-sbom.sh --ui # opens http://localhost:8080; results save to the current folder
# Windows: double-click scripts\sbom-ui.bat
```
Enter a project name and version, pick a scan target (current folder, GitHub URL, ZIP, SBOM, firmware upload, or Docker image), click Run scan, then view or download the results; live logs stream as it runs. To scan a folder outside the launch directory, add `--mount ` (repeatable, or `--mount /` for the whole host); the desktop app has an Add folder button for the same.
### CLI (advanced)
```bash
docker pull ghcr.io/sktelecom/bomlens:latest # aliases: sbom-generator and sbom-scanner serve the same image
./scripts/scan-sbom.sh --project MyApp --version 1.0.0 --target examples/nodejs --all --generate-only
```
On Windows, run the same command through `scripts\scan-sbom.bat` (Git for Windows required). Outputs land in a `{Project}_{Version}/` subfolder, prefixed `{Project}_{Version}_…`: `bom.json` (SBOM), `NOTICE.{txt,html}`, `risk-report.{md,html}`, and `security.{json,md,html}`; add `--spdx` for an SPDX 2.3 copy. Other inputs and every option are in the [CLI reference](docs/reference/cli.md) and the [input-scenarios guide](docs/guides/by-input.md).
## Contributing & License
Issues and PRs welcome — see [CONTRIBUTING.md](CONTRIBUTING.en.md) ([한국어](CONTRIBUTING.md)) and [GitHub Issues](https://github.com/sktelecom/bomlens/issues).
Apache License 2.0 · © 2026 SK Telecom Co., Ltd. Bundled third-party tools keep their own licenses — see [NOTICE](NOTICE) and [THIRD_PARTY_LICENSES.md](THIRD_PARTY_LICENSES.md).