← Package directory
Available on winget

Install SBOM Tool

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.

Install with winget
winget install --id Microsoft.SBOMTool
Upgrade
winget upgrade --id Microsoft.SBOMTool
Uninstall
winget uninstall --id Microsoft.SBOMTool

About SBOM Tool

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.

What's new in 4.1.5

⚙️ Changes - Bump component detection to 6.2.1 by @sebasgomez238 (#1359) - Fix CG alert - .NET SDK by @ZhengHong-Tan (#1334) - Remove GH packages release step from pipeline by @sfoslund (#1333) - Fix release pipeline internal feed release by @sfoslund (#1325)

Read release notes

Version history

Version Updated Notes
4.1.5 Unknown ⚙️ Changes - Bump component detection to 6.2.1 by @sebasgomez238 (#1359) - Fix CG alert - .NET SDK by @ZhengHong-Tan (#1334) - Remove GH packages release step from pipeline by @sfoslund (#1333) - Fix release pipeline int...
4.1.1 Unknown ⚙️ Changes - Temporarily make NI policy permissive by @pragnya17 (#1157) - Scope FileHasher awaiting to just aggregation by @DaveTryon (#1160) - Add telemetry to record depends on relationships by @pragnya17 (#1153) - Ex...
4.0.3 Unknown ⚙️ Changes - Bump component-detection from 5.2.13 to 5.2.19 by @DaveTryon (#1051) - Add migration guide to V4 API by @DaveTryon (#1028) - Add documentation for SPDX 3.0 by @pragnya17 (#1027)
3.1.0 Unknown ⚙️ Changes - Add interface pin, split IConfiguration to be non-breaking by @DaveTryon (#919) - Update metadata contract to be backcompatible with SPDX 2.2 parser by @pragnya17 (#918) - Remove unnecessary parser errors wh...
3.0.1 Unknown No notes
2.2.6 Unknown No notes
1.5.2 Unknown No notes