Experimental prototype · 11 September 2026
One SBOM.What to investigate.
CRAFT reads a product’s software bill of materials and lists the components and vulnerabilities to verify.
- CycloneDX
- SPDX JSON
- No account
- File not stored
The problem
The first question still takes days.
In a manufacturer of 50 to 300 people, the software bill of materials lives in a spreadsheet, a build pipeline, and two engineers’ heads. When a library shows up in an alert, nobody can immediately say which shipped products embed it.
How it works
From file to table, in three steps.
01
Upload
A CycloneDX or SPDX JSON SBOM, without creating an account.
02
Analysis
Components are extracted, then matched against public vulnerabilities.
03
Understand
A table of items to investigate, with no verdict on your product.
Preview
What you see after upload
Counters and rows come from your file.
Preview of the results table structure.
your-sbom.json
CycloneDX or SPDX
- Components
- Identified vulnerabilities
- Critical
- To investigate
| Component | Version | CVE | Severity | Action |
|---|---|---|---|---|
Analysis
Analyze an SBOM
You will see the number of components, potentially applicable CVEs, their severity, and the action: investigate.
Drop a JSON SBOM
CycloneDX preferred. SPDX JSON accepted. 10 MB max. Public PURLs go to OSV; internal PURLs are not sent.
CycloneDX preferred. SPDX JSON accepted. 10 MB max. Public PURLs go to OSV; internal PURLs are not sent.
Who builds this
Built by one person.
Jean-Pierre
Founder of CRAFT · SkyZon
Engineering student, ESME Sudria
I am building CRAFT for SMEs that manufacture a digital product under their own brand: those that will have to prove what is inside, without a €60k consultancy or a scanner designed for a large account.
LinkedIn profileNext
A file is not always enough.
If you do not have an SBOM yet, an eight-question diagnostic produces a PDF report. Otherwise, a written message is enough: no appointment required.