Rust CLI · Homebrew tap
Find vulnerable packages. Fix them safely.
Find the security vulnerabilities hiding in your project — and fix them in just a few commands.
brew install cloudengine-labs/tap/sbom-sentinel$ sbom-sentinel scan .
Building CycloneDX SBOM…
✓ Project manifests discovered
✓ Known vulnerabilities checked
✓ Report written to .sbom-assessment/…
Next: sbom-sentinel report .sbom-assessment
A safer path to a fix
Five steps, one command at a time.
Every stage produces something you can inspect. Nothing is silently changed along the way.
- 01
Scan your project
SBOM Sentinel reads your project's manifests, lists every package your app depends on, and checks each one against databases of known security vulnerabilities.
sbom-sentinel scan . - 02
Review the report
Get a plain, focused list of the vulnerable packages in your project — what's affected and how serious it is.
sbom-sentinel report .sbom-assessment - 03
Create a fix plan
Generate a plan that upgrades each risky package to a safe version. This step changes nothing in your project yet.
sbom-sentinel remediate .sbom-assessment - 04
Preview every change
Run the plan without --apply to review actions and detect manifests changed since the scan.
sbom-sentinel apply-remediation <plan> - 05
Apply with confirmation
Apply only after checking the preview and supplying the unique plan ID.
sbom-sentinel apply-remediation <plan> --apply --confirm <plan-id>
Works across your stack
Eight ecosystems. One scan.
Automatic manifest detection finds supported projects recursively. You can also choose one language or scan only the top level.
What you receive
Readable report
A focused Markdown view of vulnerable packages.
Issues CSV
A portable list for triage and follow-up.
Normalized findings
Structured findings plus raw scanner output.
Remediation plan
Exact actions, digests, and confirmation ID.
Preview by default
Applying a remediation plan without --apply is a dry run.
Changes are rechecked
Manifest digests are validated again before any package manager runs.
You stay in control
A real change requires both --apply and the unique plan ID.
Continuous integration
Fail the build, not the release.
Add one line to your pipeline. If the scan finds a high or critical vulnerability, it exits with an error and the build stops — before anything risky ships.
sbom-sentinel scan . --fail-on highHow it is different
Why not just use what's already there?
Most builders already have some way to check dependencies. Here's what SBOM Sentinel does differently.
Runs on your machine. No account.
Install it and start scanning — no sign-up, no telemetry. Once the vulnerability databases are downloaded, it keeps working offline.
Usually cloud scanners ask for an account and send your project data to a service. Dependabot works through GitHub.
Two vulnerability databases, one clean list.
Findings from two independent databases are merged, de-duplicated, and sorted by severity — so one issue never shows up twice.
Usually tools check a single database. npm audit sees only npm's.
You approve before anything changes.
It writes a fix plan, shows you a preview, and applies only when you pass --apply plus the plan's unique ID. The plan records file hashes, so it refuses to run if your files changed since the scan.
Usually npm audit fix --force edits your project straight away. Dependabot opens pull requests instead — a different, and also useful, review point.
It fixes the packages you didn't choose.
Most vulnerabilities hide in packages your dependencies pulled in. It separates those from the ones you added directly, keeps dev-only tools in their own section, and pins transitive packages with overrides, resolutions, or pnpm.overrides. npm, pnpm, Yarn, and Bun are all detected.
Usually tools only bump the dependencies you listed yourself.
One tool, eight ecosystems, shareable results.
Scan a Node, Python, Rust, Go, Java, .NET, Ruby, or PHP project with the same commands, and export a machine-readable inventory you can hand to a security team.
Usually language-specific auditors cover one ecosystem each.
Documentation
Start with a scan, review your fix plan, then apply only the changes you approve.
Read the full guideYour first scan
sbom-sentinel scan .Run it from your project folder. The command prints the report's location; use that folder to review findings and create a fix plan. Run your tests and scan again after applying fixes.
The full guide covers macOS, Linux and Windows installation, CI checks, supported ecosystems, fixing limits and troubleshooting.
Scanning supports eight ecosystems. Automatic fixing is most complete for Node (JavaScript & TypeScript); other ecosystems have specific limits.
Start here
Ready to run your first scan?
Install with Homebrew, open a project directory, then run sbom-sentinel for the built-in guide.
brew install cloudengine-labs/tap/sbom-sentinelPlatform support
SBOM Sentinel is built by CloudEngine Labs.
Questions? Contact us