SBOMFlow reads real builds — firmware trees (Buildroot, Yocto,
Zephyr), container images, lockfiles across the common and the
embedded ecosystems (Conan for C/C++, NuGet, npm, pnpm, yarn, bun,
Go, Rust, Python, Ruby, PHP, Swift and more), and the SBOMs your
suppliers send — and generates validated, reproducible CycloneDX
and SPDX from what it observed. Imported supplier data is kept
distinct from locally observed evidence, declared and file-based
licences resolve into SPDX expressions, and secure-update
artifacts (TUF/Uptane metadata, update manifests) are recorded as
evidence. Signature material such as cosign and Sigstore bundles
is recorded as present — never silently "verified".
Automatic: composition, dependency edges, licence evidence, SBOM validation.
Yours: which inputs are in scope; what a supplier claim is worth.
Supported inputs → Capability matrix →