Know exactly what ships.
bomwerk turns your repository, and for C/C++ your real build, into an SBOM you can defend in an audit. And it tells you plainly what it could not check.
- C/C++
- C#/.NET
- Python
- JS/TS
- Rust
- Go
- Java
- Open source, Apache-2.0
- Runs offline, no telemetry
- CycloneDX 1.6 and SPDX 3.0.1
warning: submodule 'third_party/openssl' not initialized
components: 55 · 44 matchable by an advisory database
✗ pkg:generic/zlib@1.2.11 (third_party/zlib): CVE-2022-37434 (9.8 Critical) … [cpe-fallback, lower confidence] report: report.html (self-contained HTML)
A vendored zlib with no manifest, found and matched. The uninitialized submodule is reported, not silently skipped.
An SBOM is only as useful as its evidence.
Dependency evidence is spread across manifests, build files, vendored source and linked artifacts. A useful inventory makes those limits visible instead of hiding them.
C/C++ evidence is scattered.
There is no universal lockfile. Vendored source, submodules and prebuilt archives hold components a manifest-only inventory never sees.
The reporting clock is running.
Manufacturers in scope send an early warning within 24 hours of becoming aware of an actively exploited vulnerability, through the ENISA Single Reporting Platform.
€15M or 2.5%.
Breaching the CRA's essential requirements or reporting obligations can cost up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.
From repository to evidence in three steps.
The open-source CLI does the work on your machine. No server to run, nothing uploaded.
-
1Scan the repository$ bomwerk scan .
Reads lockfiles, manifests, vendored source and git submodules across npm, Python, Go, Rust, Java, .NET, PHP, Ruby, Dart, Conan, vcpkg and CMake. Matches components against OSV.
SBOM + a coverage line showing what was not checked -
2Prove it with the buildC/C++$ bomwerk observe -- make
Records what your compiler and linker really touched. Then
trimflags components the build never used andbinscanreads the binaries it produced.An inventory backed by the real build -
3Hand it over$ bomwerk scan . -f spdx
CycloneDX 1.6 or SPDX 3.0.1 JSON, plus a self-contained HTML report that works offline and prints to PDF. The same input always gives the same bytes.
Files an auditor or customer can check
See the full build-evidence workflow
After you ship: monitor, triage, report.
The commercial extension keeps watching the releases you registered. It is in preview and not yet generally available. Talk to us if you want early access.
- Registereach product release and its SBOM
- MonitorOSV and CISA KEV for new advisories
- Triagerecord affected or not, as VEX
- Draftthe CRA report that your team reviews and submits
Status, honestly: steps 1 to 3 are in preview: on the main branch, tested and usable from source, with no tagged release yet. Signed prebuilt binaries are planned. What is shipped, preview and planned
Pick the question you need answered.
What does our build really link?
Build the CLI, scan a repository and check the result against a real build, all on your own machine.
Get started with the CLI product securityWhat is our current SBOM missing?
We assess one repository with you, compare it with what you use today and walk you through the gaps.
Request a free scan compliance and leadershipWhere do we stand on the CRA?
Fifteen yes-or-no questions across visibility, monitoring, response, documentation and ownership.
Download the checklistDon't take our word for it. Try to break it.
bomwerk/nightmare is a small C project built to defeat manifest-only scanners: a vendored library with a known CVE, an uninitialized submodule, a forked dependency, prebuilt binaries with no manifest. Its hand-written ground truth lists the answer a correct scanner should give, and bomwerk is scored against it too, misses included.
- Every command on this siteis checked against the CLI's own
--helpby an automated site check. - Every open-source capabilitycites the test behind it in the public capability ledger.
- Every gapstays visible in the output as "not checked", never as a reassuring zero.
Keep the tools you have. Add the evidence they were not built to collect.
bomwerk replaces none of these. Each answers a different question. bomwerk answers one: what is inside the product you ship, and how sure can you be?
"Built for" summarises what each tool is documented to do. It is not a test result, and we have not yet published a head-to-head benchmark. The fair comparison is on your own repository: run your current tool and bomwerk on the same code, or ask us to do it with you. If bomwerk adds nothing, the result will say so.
Your source code is not the price of the assessment.
-
No telemetry. The CLI never reports on you, your machine or your usage.
-
Works air-gapped.
--offlineanswers from the local cache and contacts nothing. -
Every host, listed. Only package identifiers are sent, never source. The allowlist is enforced in the network layer, not just documented.
-
Sharing is your call. For an assisted scan we agree how your code is handled before anything moves.
This website is separate from the product: "no telemetry" and "contacts nothing" above describe the CLI, not this page. The site uses Plausible for cookie-free analytics and Formspree for the form below — submitting that form keeps your enquiry on file for up to 90 days. Privacy notice.
bomwerk makes outbound HTTPS requests to these hosts, and to no others.
api.osv.dev advisory matching, default
services.nvd.nist.gov --cpe-fallback only
crates.io · pypi.org · rubygems.org --license-fallback only
There are no inbound ports and no telemetry.
Is your team ready for the CRA? Find out in 15 minutes.
A two-page self-assessment for teams shipping C/C++ and mixed-language products into the EU. Each unchecked box is a gap worth closing.
- Visibility Do you know what is inside each product?
- Monitoring Would you notice a new exploited vulnerability?
- Response Could you send an early warning within 24 hours?
- Documentation Could you show your evidence to an auditor?
- Ownership Who is actually driving this?
No email address required. Educational material, not legal advice.
Request a free scan of one repo.
Tell us what you want to understand. We agree how the repository is handled, run the assessment, and explain both the result and its limits.
We reply within one working day. Or write to info@bomwerk.com.
What happens next
Formspree stores the submission and delivers it to our mailbox. We use it only to answer your enquiry and delete it 90 days after the enquiry closes. Privacy notice.
Straight answers.
Does my code leave my machines?
--offline. If you ask us to assess a repository you share, that transfer is deliberate and agreed first. The website form should never contain source code or secrets.