Hello SPDX outreach team, I would like to request a listing for BomLens on the SPDX Tools page ( https://spdx.dev/use/spdx-tools/).
- Name: BomLens - Publisher: SK Telecom - License: Apache-2.0 - Repository: https://github.com/sktelecom/sbom-tools - Documentation: https://sktelecom.github.io/sbom-tools/ BomLens is a local-first SBOM generator and open source risk assessor. It generates SBOMs from source code, container images, binaries, and firmware, and produces open source NOTICE files plus security/license risk reports — via CLI, web UI, or a desktop app. On SPDX compatibility, per your listing guidance: BomLens ingests supplier-submitted SPDX documents (JSON and tag-value), validates them, and converts them to CycloneDX for downstream analysis. License handling is SPDX-based throughout — detected licenses are normalized to SPDX license identifiers, and the generated NOTICE files group components by SPDX id. SPDX ingestion is exercised by fixtures in our CI test suite. Please let me know if you need anything else for the listing. Best regards, Haksung Jang Open Source Program Manager, SK Telecom Chair, OpenChain Korea Work Group Maintainer, BomLens - https://github.com/sktelecom/sbom-tools -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#1527): https://lists.spdx.org/g/Spdx-outreach/message/1527 Mute This Topic: https://lists.spdx.org/mt/120084155/21656 Group Owner: [email protected] Unsubscribe: https://lists.spdx.org/g/Spdx-outreach/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
