Hello SPDX outreach team,

I would like to request a listing for BomLens on the SPDX Tools page (
https://spdx.dev/use/spdx-tools/).

- Name: BomLens
- Publisher: SK Telecom
- License: Apache-2.0
- Repository: https://github.com/sktelecom/sbom-tools
- Documentation: https://sktelecom.github.io/sbom-tools/

BomLens is a local-first SBOM generator and open source risk assessor. It
generates SBOMs from source code, container images, binaries, and firmware,
and produces open source NOTICE files plus security/license risk reports —
via CLI, web UI, or a desktop app.

On SPDX compatibility, per your listing guidance: BomLens ingests
supplier-submitted SPDX documents (JSON and tag-value), validates them, and
converts them to CycloneDX for downstream analysis. License handling is
SPDX-based throughout — detected licenses are normalized to SPDX license
identifiers, and the generated NOTICE files group components by SPDX id.
SPDX ingestion is exercised by fixtures in our CI test suite.

Please let me know if you need anything else for the listing.

Best regards,

Haksung Jang
Open Source Program Manager, SK Telecom
Chair, OpenChain Korea Work Group
Maintainer, BomLens - https://github.com/sktelecom/sbom-tools


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#1527): https://lists.spdx.org/g/Spdx-outreach/message/1527
Mute This Topic: https://lists.spdx.org/mt/120084155/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/Spdx-outreach/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to