Search
Search the docs, blog, and marketplace.
Bomly CLI
Bomly is a free, open-source CLI that scans your projects, container images, Git refs, and SBOMs, explains where each dependency came from, and surfaces vulnerability and license data when you ask for it.
A Software Bill of Materials, on demand.
A Software Bill of Materials is a complete list of the packages your software depends on. Bomly builds one for any project — by reading manifests, lock files, container layers, or existing SBOMs — and tells you what those packages mean: where they came from, what license they ship under, and which ones have known vulnerabilities.
It is a single binary. Run it on your laptop, in CI, or as an MCP tool for an AI agent. There is nothing to host.
Source trees
manifests, lock files
Container images
OCI / Docker
Git refs
branch, tag, or commit
SBOMs
SPDX or CycloneDX
Three commands. Real answers.
Scan, explain, diff. The same answers whether you start from a source tree, a container image, a Git ref, or an SBOM.
Resolve the full graph, enrich it, and fail the run when policy says so.
Or walk the graph by hand.
Add --interactive to a scan and Bomly opens a terminal UI instead of printing a report. Fuzzy-find a package, see how it landed in your build, and pivot between its advisories, license, and policy findings without writing anything to disk.
- 1Overview — totals by ecosystem and severity
- 2Components — the project tree and every dependency path
- 3Vulnerabilities — findings grouped by package
- 4Licenses — inventory and conflicts
- 5Findings — policy hits with reasons
- 6Source — detected manifests and lockfiles
One CLI for the whole pipeline.
Scan, enrich, audit, explain, and diff — across every major ecosystem developers ship today.
One CLI for the whole pipeline.
Scan, enrich, audit, explain, and diff — across every major ecosystem developers ship today.
Scan anywhere
Source trees, container images, Git refs, or existing SBOMs. One command, four input shapes.
Native detectors, full graph
Native parsers for Go, npm, pnpm, yarn, Maven, Gradle, Python, Ruby, PHP, NuGet, Cargo, and more resolve the full transitive graph and tag each package runtime or dev. Syft covers the long tail.
SBOMs in one run
Produce SPDX 2.3 and CycloneDX 1.6 JSON side by side with one `-o` flag per format.
Vulnerability data on demand
Enrich with OSV, CISA KEV, deps.dev, ClearlyDefined, and endoflife.date via --enrich. No outbound calls without it.
SARIF for CI
Emit SARIF 2.1.0 so vulnerability findings show up natively in GitHub, GitLab, and Azure DevOps. Stable exit codes (0 / 2 / 4) let scripts branch on outcome.
License policy
Every package carries its SPDX license. Allow or deny licenses with --allow-license and --deny-license, and the audit fails on any you did not approve.
Extensible by design
Detectors, matchers, auditors, and analyzers all speak the same gRPC contract Bomly uses internally. Ship your own as a separate binary — see Plugins.
0+
ecosystems supported — native parsers for the most common, plus Syft for the long tail
0
ways to consume output — text, JSON, SARIF, SPDX, CycloneDX, interactive TUI
MCP
ready for AI agents (Claude, Cursor, custom)
Apache 2.0
free, open source, no telemetry
Built for AI agents, too.
Run bomly mcp serve and any MCP-aware agent — Claude Code, Cursor, your own — can call bomly_scan, bomly_explain, and bomly_diff as tools. Every CLI flag is exposed. The agent gets the same answers you would, in JSON it can reason over.
- Four tools, structured output. Scan, explain, diff, and list plugins. Results come back as JSON that is easy to summarize and reason about.
- Stdio MCP, no daemon. Your agent launches Bomly per task — from the installed CLI, or with
npx -y bomly-mcpand no install at all. No long-running server, no service to operate. - Flag parity with the CLI. Anything you can pass on the command line — scope filters, output formats, audit policy — is reachable from the agent.
$ bomly mcp serveStarting Bomly MCP server (stdio) ...Registered tools: bomly_scan Scan and get compact, remediation-grouped findings. bomly_explain Dependency paths, advisories, and fix context for one package. bomly_diff Security delta between two Git refs. bomly_plugins List registered Bomly plugins.Awaiting client on stdio ...> Why is lodash in our web bundle?tool: bomly.explain { "target": "./web", "package": "lodash" }{ "ecosystem": "npm", "package": "[email protected]", "introducedBy": [ "web → [email protected]", " → [email protected]", " → [email protected]", " → [email protected]" ], "directDependency": false}Lodash is pulled in transitively through ui-kit'suse of lodash.template. It is not a direct dep.Extend every stage of the pipeline.
Detection, enrichment, audit, and reachability analysis are each a contract. Implement one as a small Go binary, hand it to Bomly over gRPC, and it runs beside the built-ins with the same access to graphs, packages, and findings.
Detectors
Plug in your own ecosystem reader. If you can express "these files mean these packages," Bomly turns it into a dependency graph the rest of the pipeline understands.
Matchers
Bring an extra signal — internal advisories, license overrides, package provenance — and attach it to packages alongside OSV and KEV data.
Auditors
Turn enriched graphs into findings. Encode your team's policy as a plugin and let `--audit` do the rest.
Analyzers
Bring your own reachability analysis. During `--analyze`, your plugin marks which vulnerable packages the code actually reaches. Experimental, like the built-in analyzers.
Designed to run in sensitive environments.
Bomly is a security tool. Here is exactly what it does — and does not — do.
Apache 2.0
Free and open source. No proprietary lock-in, no subscription required to run locally or in CI.
No telemetry
Bomly never phones home. No usage tracking, no crash reporting, and no network calls unless you opt in to enrichment.
Network enrichment is opt-in
Vulnerability and license enrichment runs only when you pass --enrich. Nothing leaves your machine otherwise.
Checksummed releases
Every release ships a SHA256SUMS file so you can pin to a known binary before deploying in CI.
SARIF & CI output
Emit findings as SARIF and gate merges on policy. Works with GitHub Code Scanning and any SARIF-aware CI.
Open-source detectors & matchers
All ecosystem detectors and vulnerability matchers are in the public repo — auditable and extensible.
Opt-in enrichment pulls from OSV, CISA KEV, deps.dev, ClearlyDefined, and endoflife.date — publicly available, open data sources.
Some detectors based on build tools (such as Maven or Gradle) may resolve packages from the relevant package registry as part of constructing the dependency graph. This is inherent to how those build tools work and applies only to projects that use those ecosystems.
Install Bomly in under a minute.
Bomly is one binary. Pick the method that fits your environment and you're ready to run bomly scan.
brew install bomly-dev/tap/bomlyMore options — prebuilt binaries, Linux packages, checksum verification, version pinning — are in the installation docs. Full release notes and checksums: github.com/bomly-dev/bomly-cli/releases
Register Bomly as an MCP server in your agent of choice. Here is the snippet for Claude Code's ~/.claude.json:
{
"mcpServers": {
"bomly": {
"command": "bomly",
"args": ["mcp", "serve"]
}
}
}No CLI install needed for MCP: use "command": "npx" with "args": ["-y", "bomly-mcp"] instead. See the MCP page for Cursor and the full agent workflow.
Read about how Bomly works
Each guide explains one piece of the pipeline — what it does, when it runs, and how to configure or extend it.
Try Bomly on your project.
One binary, no signup, no telemetry. Install it, run bomly scan, see what you depend on.