Skip to content

Search

Search the docs, blog, and marketplace.

v0.28.2 is out

Bomly CLI

Bomly is a free, open-source CLI that scans your projects, container images, Git refs, and SBOMs, explains where each dependency came from, and surfaces vulnerability and license data when you ask for it.

Read the docs
npmGoPyPIMavenCargo+ 25 more ecosystems
What is Bomly

A Software Bill of Materials, on demand.

A Software Bill of Materials is a complete list of the packages your software depends on. Bomly builds one for any project — by reading manifests, lock files, container layers, or existing SBOMs — and tells you what those packages mean: where they came from, what license they ship under, and which ones have known vulnerabilities.

It is a single binary. Run it on your laptop, in CI, or as an MCP tool for an AI agent. There is nothing to host.

Source trees

manifests, lock files

Container images

OCI / Docker

Git refs

branch, tag, or commit

SBOMs

SPDX or CycloneDX

one dependency graph, one set of answers
Commands

Three commands. Real answers.

Scan, explain, diff. The same answers whether you start from a source tree, a container image, a Git ref, or an SBOM.

Resolve the full graph, enrich it, and fail the run when policy says so.

bomly scan
Interactive mode

Or walk the graph by hand.

Add --interactive to a scan and Bomly opens a terminal UI instead of printing a report. Fuzzy-find a package, see how it landed in your build, and pivot between its advisories, license, and policy findings without writing anything to disk.

  • 1Overview — totals by ecosystem and severity
  • 2Components — the project tree and every dependency path
  • 3Vulnerabilities — findings grouped by package
  • 4Licenses — inventory and conflicts
  • 5Findings — policy hits with reasons
  • 6Source — detected manifests and lockfiles
bomly scan --enrich --audit --interactive
Features

One CLI for the whole pipeline.

Scan, enrich, audit, explain, and diff — across every major ecosystem developers ship today.

01

Scan anywhere

Source trees, container images, Git refs, or existing SBOMs. One command, four input shapes.

02

Native detectors, full graph

Native parsers for Go, npm, pnpm, yarn, Maven, Gradle, Python, Ruby, PHP, NuGet, Cargo, and more resolve the full transitive graph and tag each package runtime or dev. Syft covers the long tail.

03

SBOMs in one run

Produce SPDX 2.3 and CycloneDX 1.6 JSON side by side with one `-o` flag per format.

04

Vulnerability data on demand

Enrich with OSV, CISA KEV, deps.dev, ClearlyDefined, and endoflife.date via --enrich. No outbound calls without it.

05

SARIF for CI

Emit SARIF 2.1.0 so vulnerability findings show up natively in GitHub, GitLab, and Azure DevOps. Stable exit codes (0 / 2 / 4) let scripts branch on outcome.

06

License policy

Every package carries its SPDX license. Allow or deny licenses with --allow-license and --deny-license, and the audit fails on any you did not approve.

07

Extensible by design

Detectors, matchers, auditors, and analyzers all speak the same gRPC contract Bomly uses internally. Ship your own as a separate binary — see Plugins.

0+

ecosystems supported — native parsers for the most common, plus Syft for the long tail

0

ways to consume output — text, JSON, SARIF, SPDX, CycloneDX, interactive TUI

MCP

ready for AI agents (Claude, Cursor, custom)

Apache 2.0

free, open source, no telemetry

AI agents

Built for AI agents, too.

Run bomly mcp serve and any MCP-aware agent — Claude Code, Cursor, your own — can call bomly_scan, bomly_explain, and bomly_diff as tools. Every CLI flag is exposed. The agent gets the same answers you would, in JSON it can reason over.

  • Four tools, structured output. Scan, explain, diff, and list plugins. Results come back as JSON that is easy to summarize and reason about.
  • Stdio MCP, no daemon. Your agent launches Bomly per task — from the installed CLI, or with npx -y bomly-mcp and no install at all. No long-running server, no service to operate.
  • Flag parity with the CLI. Anything you can pass on the command line — scope filters, output formats, audit policy — is reachable from the agent.
See the full agent workflow
bomly mcp serve
$ bomly mcp serveStarting Bomly MCP server (stdio) ...Registered tools: bomly_scan Scan and get compact, remediation-grouped findings. bomly_explain Dependency paths, advisories, and fix context for one package. bomly_diff Security delta between two Git refs. bomly_plugins List registered Bomly plugins.Awaiting client on stdio ...
agent transcript
> Why is lodash in our web bundle?tool: bomly.explain { "target": "./web", "package": "lodash" }{ "ecosystem": "npm", "package": "[email protected]", "introducedBy": [ "web → [email protected]", " → [email protected]", " → [email protected]", " → [email protected]" ], "directDependency": false}Lodash is pulled in transitively through ui-kit'suse of lodash.template. It is not a direct dep.
Plugins

Extend every stage of the pipeline.

Detection, enrichment, audit, and reachability analysis are each a contract. Implement one as a small Go binary, hand it to Bomly over gRPC, and it runs beside the built-ins with the same access to graphs, packages, and findings.

stage 01

Detectors

Plug in your own ecosystem reader. If you can express "these files mean these packages," Bomly turns it into a dependency graph the rest of the pipeline understands.

stage 02

Matchers

Bring an extra signal — internal advisories, license overrides, package provenance — and attach it to packages alongside OSV and KEV data.

stage 03

Auditors

Turn enriched graphs into findings. Encode your team's policy as a plugin and let `--audit` do the rest.

stage 04

Analyzers

Bring your own reachability analysis. During `--analyze`, your plugin marks which vulnerable packages the code actually reaches. Experimental, like the built-in analyzers.

Trust & security

Designed to run in sensitive environments.

Bomly is a security tool. Here is exactly what it does — and does not — do.

Apache 2.0

Free and open source. No proprietary lock-in, no subscription required to run locally or in CI.

No telemetry

Bomly never phones home. No usage tracking, no crash reporting, and no network calls unless you opt in to enrichment.

Network enrichment is opt-in

Vulnerability and license enrichment runs only when you pass --enrich. Nothing leaves your machine otherwise.

Checksummed releases

Every release ships a SHA256SUMS file so you can pin to a known binary before deploying in CI.

SARIF & CI output

Emit findings as SARIF and gate merges on policy. Works with GitHub Code Scanning and any SARIF-aware CI.

Open-source detectors & matchers

All ecosystem detectors and vulnerability matchers are in the public repo — auditable and extensible.

Opt-in enrichment pulls from OSV, CISA KEV, deps.dev, ClearlyDefined, and endoflife.date — publicly available, open data sources.

Some detectors based on build tools (such as Maven or Gradle) may resolve packages from the relevant package registry as part of constructing the dependency graph. This is inherent to how those build tools work and applies only to projects that use those ecosystems.

Install

Install Bomly in under a minute.

Bomly is one binary. Pick the method that fits your environment and you're ready to run bomly scan.

macOS & Linux · Homebrew
brew install bomly-dev/tap/bomly

More options — prebuilt binaries, Linux packages, checksum verification, version pinning — are in the installation docs. Full release notes and checksums: github.com/bomly-dev/bomly-cli/releases

Use with AI agents

Register Bomly as an MCP server in your agent of choice. Here is the snippet for Claude Code's ~/.claude.json:

~/.claude.json
{
  "mcpServers": {
    "bomly": {
      "command": "bomly",
      "args": ["mcp", "serve"]
    }
  }
}

No CLI install needed for MCP: use "command": "npx" with "args": ["-y", "bomly-mcp"] instead. See the MCP page for Cursor and the full agent workflow.

Try Bomly on your project.

One binary, no signup, no telemetry. Install it, run bomly scan, see what you depend on.

Read the docs