Experimental prototype · 11 September 2026
One SBOM.What to investigate.
CRAFTSEC reads a product’s software bill of materials and lists the components and vulnerabilities to verify.
- CycloneDX
- SPDX JSON
- No account
- File not stored
nomenclature.cdx.json
Product SBOM · CycloneDX
| Component | Version | CVE | Severity | Action |
|---|---|---|---|---|
| openssl | 3.0.8 | CVE-2024-5535 | Critical | Investigate |
| curl | 8.4.0 | CVE-2023-38545 | High | Investigate |
| zlib | 1.2.13 | CVE-2023-45853 | Medium | Investigate |
| busybox | 1.36.1 | — | None | — |
4 sample rows
Illustrative example
The problem
The first question still takes days.
In a manufacturer of 50 to 300 people, the software bill of materials lives in a spreadsheet, a build pipeline, and two engineers’ heads. When a library shows up in an alert, nobody can immediately say which shipped products embed it.
How it works
From file to table, in three steps.
01
Upload
A CycloneDX or SPDX JSON SBOM, without creating an account.
02
Analysis
Components are extracted, then matched against public vulnerabilities.
03
Understand
A table of items to investigate, with no verdict on your product.
Preview
What you see after upload
Counters and rows come from your file.
Illustrative example
- Components
- Identified vulnerabilities
- Critical
- To investigate
- Component
- Version
- CVE
- Severity
- Action
Questions
Before you upload a file.
What is CRAFTSEC?
CRAFTSEC reads a CycloneDX or SPDX SBOM and lists the components and vulnerabilities to investigate. It is an experimental prototype, not an attestation.
Which files are accepted?
A CycloneDX or SPDX JSON SBOM, up to 10 MB. No account. CycloneDX is the most reliable format here.
What happens to the uploaded SBOM?
It is read in memory for the duration of the analysis, then discarded. It is not stored in a database. Only public package identifiers (PURLs) are sent to OSV. Internal PURLs do not leave the service.
Does CRAFTSEC certify my product?
No. The analysis is a preparation aid. A displayed CVE is not confirmation that the product is vulnerable. A competent person must verify.
Do I need an account?
No. The result stays in your browser until the tab is closed. The result URL is not indexed.
I do not have an SBOM yet. What can I do?
An eight-question diagnostic produces a PDF report: exposure score, gaps, checklist. Otherwise, a written message is enough.
Analysis
Analyze an SBOM
You will see the number of components, potentially applicable CVEs, their severity, and the action: investigate.
Drop a JSON SBOM
CycloneDX preferred. SPDX JSON accepted. 10 MB max. Public PURLs go to OSV; internal PURLs are not sent.
CycloneDX preferred. SPDX JSON accepted. 10 MB max. Public PURLs go to OSV; internal PURLs are not sent.
Who builds this
Built by one person.
Jean-Pierre Dupuis
Founder of CRAFTSEC · SkyZon
Engineering student, ESME Sudria
I am building CRAFTSEC for SMEs that manufacture a digital product under their own brand: those that will have to prove what is inside, without a €60k consultancy or a scanner designed for a large account.
LinkedIn profileNext
A file is not always enough.
If you do not have an SBOM yet, an eight-question diagnostic produces a PDF report. Otherwise, a written message is enough: no appointment required.