Skip to content

Experimental prototype · 11 September 2026

One SBOM.What to investigate.

CRAFTSEC reads a product’s software bill of materials and lists the components and vulnerabilities to verify.

  • CycloneDX
  • SPDX JSON
  • No account
  • File not stored

nomenclature.cdx.json

Product SBOM · CycloneDX

GridFilterSort
Preview of the results table structure.
ComponentVersionCVESeverityAction
openssl3.0.8CVE-2024-5535CriticalInvestigate
curl8.4.0CVE-2023-38545HighInvestigate
zlib1.2.13CVE-2023-45853MediumInvestigate
busybox1.36.1—None—

4 sample rows

Illustrative example

The problem

The first question still takes days.

In a manufacturer of 50 to 300 people, the software bill of materials lives in a spreadsheet, a build pipeline, and two engineers’ heads. When a library shows up in an alert, nobody can immediately say which shipped products embed it.

How it works

From file to table, in three steps.

  1. 01

    Upload

    A CycloneDX or SPDX JSON SBOM, without creating an account.

  2. 02

    Analysis

    Components are extracted, then matched against public vulnerabilities.

  3. 03

    Understand

    A table of items to investigate, with no verdict on your product.

Preview

What you see after upload

Counters and rows come from your file.

Illustrative example

Components
Identified vulnerabilities
Critical
To investigate
  • Component
  • Version
  • CVE
  • Severity
  • Action

Questions

Before you upload a file.

What is CRAFTSEC?

CRAFTSEC reads a CycloneDX or SPDX SBOM and lists the components and vulnerabilities to investigate. It is an experimental prototype, not an attestation.

Which files are accepted?

A CycloneDX or SPDX JSON SBOM, up to 10 MB. No account. CycloneDX is the most reliable format here.

What happens to the uploaded SBOM?

It is read in memory for the duration of the analysis, then discarded. It is not stored in a database. Only public package identifiers (PURLs) are sent to OSV. Internal PURLs do not leave the service.

Does CRAFTSEC certify my product?

No. The analysis is a preparation aid. A displayed CVE is not confirmation that the product is vulnerable. A competent person must verify.

Do I need an account?

No. The result stays in your browser until the tab is closed. The result URL is not indexed.

I do not have an SBOM yet. What can I do?

An eight-question diagnostic produces a PDF report: exposure score, gaps, checklist. Otherwise, a written message is enough.

Analysis

Analyze an SBOM

You will see the number of components, potentially applicable CVEs, their severity, and the action: investigate.

Drop a JSON SBOM

CycloneDX preferred. SPDX JSON accepted. 10 MB max. Public PURLs go to OSV; internal PURLs are not sent.

CycloneDX preferred. SPDX JSON accepted. 10 MB max. Public PURLs go to OSV; internal PURLs are not sent.

Who builds this

Built by one person.

Jean-Pierre Dupuis

Founder of CRAFTSEC · SkyZon

Engineering student, ESME Sudria

I am building CRAFTSEC for SMEs that manufacture a digital product under their own brand: those that will have to prove what is inside, without a €60k consultancy or a scanner designed for a large account.

LinkedIn profile

Next

A file is not always enough.

If you do not have an SBOM yet, an eight-question diagnostic produces a PDF report. Otherwise, a written message is enough: no appointment required.