Bomly is a software publisher operating through its GitHub organization at bomly-dev, where it maintains a focused, open-source portfolio centered on software supply chain transparency. Its flagship and currently sole product, Bomly CLI, is a free, open-source command-line tool designed for dependency intelligence and Software Bill of Materials (SBOM) analysis. The tool targets developers, security engineers, and DevOps teams who need visibility into the third-party components embedded in their applications, a concern that has grown central to modern software development as open-source dependencies proliferate and supply chain attacks become more common. Typical use cases include generating and inspecting SBOMs to catalog every dependency in a project, identifying outdated or vulnerable packages, auditing licensing obligations across transitive dependencies, and integrating these checks into continuous integration and delivery pipelines so that risky components are flagged before deployment. As a command-line utility, Bomly CLI fits naturally into scripted and automated workflows, allowing teams to enforce dependency policies, produce compliance documentation, and respond quickly to newly disclosed vulnerabilities such as those tracked in public advisory databases. The publisher's open-source distribution model means the tool can be freely inspected, modified, and contributed to by the community, aligning with the transparency goals of the SBOM movement itself. With a compact catalog of one package, Bomly represents a specialized, single-purpose publisher concentrating its efforts on the software composition analysis and supply chain security category rather than offering a broad suite of unrelated products.

Bomly CLI

Free, open-source CLI for dependency intelligence and SBOM analysis.

Details