sbom.wiki

The Living Encyclopedia of Software Dependencies

Libraries
Frameworks
Runtimes
Tools

The Component Ecosystem

Explore the interconnected species of the software dependency world. Each cell represents a living component in the SBOM ecosystem.

Library

Package Registries

The flowering plants of software: npm, PyPI, crates.io -- each package a unique bloom in the digital garden.

Framework

Structural Trees

React, Django, Rails: the ancient trees that form the canopy, providing shelter for the ecosystem beneath.

Runtime

Root Systems

Node.js, JVM, Python: the underground root networks that nourish everything growing above.

Tool

Build Instruments

Webpack, Cargo, Maven: the fruit-bearing branches that compile, bundle, and distribute nourishment.

Library

Cryptographic Flora

OpenSSL, libsodium, ring: delicate cryptographic flowers whose pollination secures the entire garden.

Framework

Web Scaffolds

Express, Spring, FastAPI: the scaffold trees whose architecture supports countless species of application.

Runtime

Container Mycelium

Docker, Kubernetes: the mycelial networks connecting disparate organisms across the software forest floor.

Tool

Security Scanners

Trivy, Grype, Snyk: the pollinators that inspect and verify the health of every organism in the ecosystem.

Library

Data Ferns

Lodash, Pandas, serde: the ferns that unfurl data into usable forms across the forest floor.

The Dependency Canopy

A panoramic view of the software dependency tree -- packages as flowers, dependencies as stems, vulnerabilities as thorns.

Libraries
Frameworks
Runtimes
Tools
SPDX

Software Package Data Exchange

An open standard for communicating software bill of materials information, including provenance, license, and security details.

CycloneDX

OWASP CycloneDX

A lightweight SBOM specification designed for use in application security contexts and supply chain component analysis.

SWID

Software Identification Tags

ISO/IEC 19770-2 standard providing a transparent framework for software lifecycle management and identification.