How to use SBOM Inventory Comparator
- Supply the before sbom (json) and after sbom (json) using the supported input described beside the controls.
- Review the selected options and the declared scope, then run the sbom inventory comparator.
- Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.
Example: SBOM Inventory Comparator
Compare supplied CycloneDX/SPDX component versions, identities and declared licenses. This example uses synthetic public data.
Options
- Supported formats
- Supply the named JSON versions and supported component/package structures. Unsupported formats are refused rather than treated as empty inventories.
- Component identity
- Prefer a shared exact package identifier. A name, local document ID or version string may have a different meaning in another inventory.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
An inventory difference is not a vulnerability finding
Version and licence strings describe what the supplied documents declare. They are not a current CVE lookup, dependency resolution or legal conclusion. Ambiguous identities require review instead of overwriting one component with another; cross-format comparisons need compatible identifiers.
Questions about SBOM Inventory Comparator
Does a changed version mean vulnerable?
No. This comparator has no current vulnerability feed.
Are licence changes legal advice?
No. The report compares declarations without interpreting permission or obligations.
Can ambiguous components be merged?
No. Ambiguous identities need explicit review rather than silent matching.