Skip to content

Rust CLI · Homebrew tap

Find vulnerable packages. Fix them safely.

Find the security vulnerabilities hiding in your project — and fix them in just a few commands.

brew install cloudengine-labs/tap/sbom-sentinel

$ sbom-sentinel scan .

Building CycloneDX SBOM…

✓ Project manifests discovered

✓ Known vulnerabilities checked

✓ Report written to .sbom-assessment/…

Next: sbom-sentinel report .sbom-assessment

A safer path to a fix

Five steps, one command at a time.

Every stage produces something you can inspect. Nothing is silently changed along the way.

  1. 01

    Scan your project

    SBOM Sentinel reads your project's manifests, lists every package your app depends on, and checks each one against databases of known security vulnerabilities.

    sbom-sentinel scan .
  2. 02

    Review the report

    Get a plain, focused list of the vulnerable packages in your project — what's affected and how serious it is.

    sbom-sentinel report .sbom-assessment
  3. 03

    Create a fix plan

    Generate a plan that upgrades each risky package to a safe version. This step changes nothing in your project yet.

    sbom-sentinel remediate .sbom-assessment
  4. 04

    Preview every change

    Run the plan without --apply to review actions and detect manifests changed since the scan.

    sbom-sentinel apply-remediation <plan>
  5. 05

    Apply with confirmation

    Apply only after checking the preview and supplying the unique plan ID.

    sbom-sentinel apply-remediation <plan> --apply --confirm <plan-id>

Works across your stack

Eight ecosystems. One scan.

Node (JavaScript & TypeScript)PythonRustGoJava / Gradle.NETRubyPHP

Automatic manifest detection finds supported projects recursively. You can also choose one language or scan only the top level.

What you receive

Readable report

A focused Markdown view of vulnerable packages.

Issues CSV

A portable list for triage and follow-up.

Normalized findings

Structured findings plus raw scanner output.

Remediation plan

Exact actions, digests, and confirmation ID.

Preview by default

Applying a remediation plan without --apply is a dry run.

Changes are rechecked

Manifest digests are validated again before any package manager runs.

You stay in control

A real change requires both --apply and the unique plan ID.

Continuous integration

Fail the build, not the release.

Add one line to your pipeline. If the scan finds a high or critical vulnerability, it exits with an error and the build stops — before anything risky ships.

sbom-sentinel scan . --fail-on high

How it is different

Why not just use what's already there?

Most builders already have some way to check dependencies. Here's what SBOM Sentinel does differently.

  • Runs on your machine. No account.

    Install it and start scanning — no sign-up, no telemetry. Once the vulnerability databases are downloaded, it keeps working offline.

    Usually cloud scanners ask for an account and send your project data to a service. Dependabot works through GitHub.

  • Two vulnerability databases, one clean list.

    Findings from two independent databases are merged, de-duplicated, and sorted by severity — so one issue never shows up twice.

    Usually tools check a single database. npm audit sees only npm's.

  • You approve before anything changes.

    It writes a fix plan, shows you a preview, and applies only when you pass --apply plus the plan's unique ID. The plan records file hashes, so it refuses to run if your files changed since the scan.

    Usually npm audit fix --force edits your project straight away. Dependabot opens pull requests instead — a different, and also useful, review point.

  • It fixes the packages you didn't choose.

    Most vulnerabilities hide in packages your dependencies pulled in. It separates those from the ones you added directly, keeps dev-only tools in their own section, and pins transitive packages with overrides, resolutions, or pnpm.overrides. npm, pnpm, Yarn, and Bun are all detected.

    Usually tools only bump the dependencies you listed yourself.

  • One tool, eight ecosystems, shareable results.

    Scan a Node, Python, Rust, Go, Java, .NET, Ruby, or PHP project with the same commands, and export a machine-readable inventory you can hand to a security team.

    Usually language-specific auditors cover one ecosystem each.

Documentation

Start with a scan, review your fix plan, then apply only the changes you approve.

Read the full guide

Your first scan

sbom-sentinel scan .

Run it from your project folder. The command prints the report's location; use that folder to review findings and create a fix plan. Run your tests and scan again after applying fixes.

The full guide covers macOS, Linux and Windows installation, CI checks, supported ecosystems, fixing limits and troubleshooting.

Scanning supports eight ecosystems. Automatic fixing is most complete for Node (JavaScript & TypeScript); other ecosystems have specific limits.

Start here

Ready to run your first scan?

Install with Homebrew, open a project directory, then run sbom-sentinel for the built-in guide.

brew install cloudengine-labs/tap/sbom-sentinel

Platform support

macOS — available nowLinux — available nowWindows — available via Scoop
Installation instructions

SBOM Sentinel is built by CloudEngine Labs.

Questions? Contact us