SBOM License Explorer
Explore the packages or components, license fields and explicitly declared relationships in an SPDX 2.3 or CycloneDX 1.6 JSON SBOM. Search identifiers and license values, inspect unresolved references, and save the inventory as JSON.
Key features
- Read local SPDX 2.3 and CycloneDX 1.6 JSON documents up to 2 MiB
- Show package or component identifiers, versions and license values with their source fields
- List declared relationship direction and distinguish dependency edges from other relationships
- Keep missing dependency declarations marked unknown, including SPDX packages without a complete dependency list
- Flag duplicate, missing, external and unresolved references, unresolved LicenseRefs and dependency cycles
- Filter inventory rows and download a JSON inspection report
How to use
- Paste an SPDX 2.3 or CycloneDX 1.6 JSON SBOM, choose a local JSON file, or load an example.
- Select Inspect SBOM to parse the document in your browser.
- Review the summary, package license fields and dependency declaration status.
- Inspect directed relationships and reference issues; use the search field to narrow the tables.
- Download the JSON report if needed, and verify license obligations and security findings separately.
Use cases
- Check which components lack supplied license fields before requesting more complete metadata
- Find a dependency reference whose target is missing from the supplied SBOM
- Distinguish an explicit empty CycloneDX dependsOn list from a missing dependency declaration
- Inspect SPDX LicenseRef values and whether a local extracted license definition is supplied
Frequently asked questions
Does this tool decide whether a project complies with a license?
No. It displays license IDs, names, markers and expressions as supplied. It does not interpret legal obligations, validate an expression against every license rule, or decide compatibility or compliance.
Does an empty relationship table mean a package has no dependencies?
No. Missing dependency declarations remain unknown. In CycloneDX, only a component with an explicit dependsOn array is marked as having a listed dependency set. SPDX relationship entries shown here do not establish a complete dependency list.
Will external references be fetched?
No. External document or BOM references are shown as unresolved outside the supplied document. The explorer makes no network request for them.
Which SBOM formats are supported?
JSON documents declaring SPDX 2.3 or CycloneDX 1.6 are supported. Other versions, XML, YAML, tag-value and RDF are not parsed.
Are vulnerability and policy checks included?
No. The report is a read-only metadata inventory with reference diagnostics. It does not scan source code or binaries, query vulnerabilities, check provenance or apply organizational policy.
Privacy
Your SBOM is read and parsed only in this browser tab. It is not uploaded or saved by this tool. The downloaded report contains package names, identifiers, license values and relationship details, so review it before sharing.
Comments & questions