SBOM Inventory Comparator

Compare supported CycloneDX or SPDX JSON inventories for component identities, versions and declared licences.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Compare inventories controls

CycloneDX 1.4, 1.5 or 1.6 JSON, or SPDX 2.2 or 2.3 JSON. Up to 5 MiB and 5,000 components.

The later SBOM, in the same or the other supported format. Both documents stay in your browser.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use SBOM Inventory Comparator

  1. Supply the before sbom (json) and after sbom (json) using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the sbom inventory comparator.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: SBOM Inventory Comparator

Compare supplied CycloneDX/SPDX component versions, identities and declared licenses. This example uses synthetic public data.

You add
Before SBOM (JSON): { "bomFormat": "CycloneDX", "specVersion": "1.6", "components": [ { "type": "library", "group": "org.example", "name": "logger", "version": "1.2.0", "purl": "pkg:maven/org.example/[email protected]", "bom-ref": "[email protected]", "licenses": [ { "license": { "id": "Apache-2.0" } } ] }, { "type": "library", "group": "org.example", "name": "parser", "version": "3.0.1", "purl": "pkg:npm/@example/[email protected]", "bom-ref": "[email protected]" } ] } After SBOM (JSON): { "bomFormat": "CycloneDX", "specVersion": "1.6", "components": [ { "type": "library", "group": "org.example", "name": "logger", "version": "1.3.0", "purl": "pkg:maven/org.example/[email protected]", "bom-ref": "[email protected]", "licenses": [ { "license": { "id": "Apache-2.0" } } ] }, { "type": "library", "group": "org.example", "name": "router", "version": "0.9.0", "purl": "pkg:npm/@example/[email protected]", "bom-ref": "[email protected]" } ] }
You get
1 added, 1 removed, 1 version change, 0 licence declaration changes. pkg:maven/org.example/logger | version changed | 1.2.0 | 1.3.0 | id:Apache-2.0 pkg:npm/@example/router | added | | 0.9.0 | (not declared) pkg:npm/@example/parser | removed | 3.0.1 | | (not declared)

Options

Supported formats
Supply the named JSON versions and supported component/package structures. Unsupported formats are refused rather than treated as empty inventories.
Component identity
Prefer a shared exact package identifier. A name, local document ID or version string may have a different meaning in another inventory.

Supported inputs and limits

Supported CycloneDX/SPDX JSON subset only. No XML, vulnerability feed, live package lookup, licence advice or software-composition certification.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

An inventory difference is not a vulnerability finding

Version and licence strings describe what the supplied documents declare. They are not a current CVE lookup, dependency resolution or legal conclusion. Ambiguous identities require review instead of overwriting one component with another; cross-format comparisons need compatible identifiers.

Questions about SBOM Inventory Comparator

Does a changed version mean vulnerable?

No. This comparator has no current vulnerability feed.

Are licence changes legal advice?

No. The report compares declarations without interpreting permission or obligations.

Can ambiguous components be merged?

No. Ambiguous identities need explicit review rather than silent matching.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem