Versions:
Bomly CLI is a free, open-source command-line tool published by Bomly that delivers dependency intelligence and SBOM (Software Bill of Materials) analysis directly from the terminal. Its core purpose is to help developers and security teams understand exactly what their software is made of by scanning projects, existing SBOM documents, and container images to identify every component in the dependency graph. Beyond simple enumeration, the tool explains the provenance of each dependency—showing where it originated and how it entered the codebase—which is particularly valuable for tracing transitive dependencies that might otherwise go unnoticed. When requested, Bomly CLI surfaces vulnerability information and license data tied to those components, enabling teams to assess security exposure and ensure compliance with licensing requirements without leaving their workflow. This makes it suitable for a range of use cases, including software supply chain security audits, open-source license compliance reviews, vulnerability triage during development, container image inspection in CI/CD pipelines, and general dependency hygiene for individual projects or large codebases. Falling within the developer tools and software security category—specifically the growing space of SBOM and software composition analysis utilities—Bomly CLI serves both individual developers seeking lightweight local scanning and organizations integrating dependency visibility into automated build processes. Its open-source nature allows users to inspect the tool itself, contribute improvements, and adapt it to their environments. The current version is 0.24.2, and the catalog lists 27 versions in total, indicating an actively maintained project with a substantial release history and ongoing iterative development. As a zero-cost solution, it provides an accessible entry point for teams that need dependency transparency, vulnerability awareness, and license clarity without investing in commercial platforms, while its CLI-first design ensures it fits naturally into scripting, automation, and terminal-centric development workflows.
Tags: