Bom Audit

Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk, dependency source integrity, license policy violations, and SARIF or JSON reporting for code scanning. Use when asked to audit an SBOM, assess supply-chain or dependency risk, check for compromised or malicious packages, triage which dependencies to review first, or produce SARIF from a BOM.

cdxgen 55c12d0 9.4 KB Updated

File contents

cdxgen/cdxgen/tree/main/claude-plugin/skills/bom-audit commit 55c12d0ff3

Frequently asked questions

npx skillmds@latest add cdxgen/bom-audit