SBOMPlay v0.0.7

Put work out in the open, and the feedback turns into a roadmap.

SBOMPlay was presented at Black Hat EU Arsenal 2025.

The best part was not the stage time. It was the conversations that followed both during the demo and afterwards.

We got a steady stream of questions, edge cases, and “what if” scenarios from people who actually wanted to use the tool in their own workflows. That instantly expanded the idea pool and clarified what we should prioritize next.

So before we posted anything publicly about the Arsenal release, we took a short pause, put our heads down, and shipped the updates.

At the event, we demoed SBOMPlay v0.0.4.

Today, we are releasing SBOMPlay v0.0.7, an enhanced build with significantly more capability than what we showed at Arsenal.

In GitHub terms, the change set from v0.0.4 to v0.0.7 was 61 files changed, with 19,893 additions and 8,992 deletions.

What is new in v0.0.7

Each of the updates below will be accompanied with a screenshot in the final post.

Custom SBOM support

    Screenshot of the SBOM Play interface, featuring options to analyze Software Bill of Materials from GitHub organizations, with a button to upload SBOM files and information about privacy assurances.

    Improved SBOM auditor that checks against baselines like CISA Minimum Elements and CERT-In

    A screenshot showing grade distribution and repository SBOM quality metrics for two repositories, indicating scores and compliance status with various SBOM guidelines.

    EOX detection (EOL and EOS)

      A summary of security findings displaying 172 total findings, categorized into high, medium, and warning levels, with details on dependency confusion and end-of-life support.

      Dependency confusion detection

        Screenshot showing a potential dependency confusion warning for a package not found in the public registry, highlighting a risk of vulnerability.

        Clear rate limit warnings

          GitHub API rate limit warning notification indicating current status, estimated API calls, and options to add a GitHub token or proceed with analysis.

          Explicit list of outbound hosts for paranoid self-hosting or air-gapped deployment
          Details: https://cyfinoid.github.io/sbomplay/about.html#:~:text=Paranoid%20Self%2DHost%20/%20Airgapped%20Deployment

            With that said Now its time for you to play with

            Links

            Leave a Reply

            Scroll to Top

            Discover more from Cyfinoid Research

            Subscribe now to keep reading and get access to the full archive.

            Continue reading