Integrate the Microsoft SBOM Tool with Vulnetix. Generate SPDX 2.2 or 3.0 SBOMs for any project by detecting components across 10+ package ecosystems. Upload the SPDX JSON to Vulnetix.
Install & scan
$ # Linux/macOS binary curl -Lo sbom-tool https://github.com/microsoft/sbom-tool/releases/latest/download/sbom-tool-linux-x64 chmod +x sbom-tool && sudo mv sbom-tool /usr/local/bin/ # macOS Homebrew brew install sbom-tool # .NET Global Tool dotnet tool install --global Microsoft.Sbom.DotNetTool $ sbom-tool generate -b . -bc . -pn my-project -pv 1.0.0 -ps my-organisation -nsb https://my-organisation.com/sbom
Run Microsoft SBOM Tool in CI
Scan on every push and upload the report as a workflow artifact:
- name: Generate SPDX SBOM
run: |
curl -Lo sbom-tool https://github.com/microsoft/sbom-tool/releases/latest/download/sbom-tool-linux-x64
chmod +x sbom-tool
./sbom-tool generate -b . -bc . -pn ${{ github.repository }} -pv ${{ github.sha }} -ps my-org -nsb https://my-org.com/sbom
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: ms-sbom-tool
path: _manifest/spdx_2.2/manifest.spdx.json
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under Microsoft SBOM Tool's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace Microsoft SBOM Tool. Keep running it. Vulnetix sits on top of Microsoft SBOM Tool (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Microsoft SBOM Tool is strongest at its core category and also carries features in SCA, License Compliance, just as Vulnetix spans categories.
| Capability | Vulnetix | Microsoft SBOM Tool |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ~ Detects components/dependencies from manifests but performs no vulnerability analysis |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ~ Populates component license data via ClearlyDefined API; no policy enforcement |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✓ Core purpose: generates and validates SPDX 2.2/3.0 SBOMs |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Microsoft SBOM Tool does well
- Enterprise-proven SPDX generator from Microsoft (SPDX 2.2 default, SPDX 3.0 via -mi flag) used across Microsoft's own build pipelines
- Static, build-safe component detection via the Component Detection library across .NET/NuGet, npm/Yarn, pip, Go, Maven/Gradle, Gems and Cargo from lock/manifest files
- Populates license metadata automatically through the ClearlyDefined API, plus SBOM validation and a redaction feature for sensitive file paths
- Ships in many form factors (standalone binaries, .NET tool, Docker image, NuGet API) for easy CI adoption
Where Vulnetix adds to it: Microsoft SBOM Tool generates SPDX inventory only, no vulnerability, malware, reachability or VEX. Vulnetix ingests its SBOM (and generates CycloneDX 1.7 + SPDX 2.3 natively), then adds exploit-intel prioritisation, reachability, versioned VEX and license policy on top. Better together: keep MS SBOM Tool for SPDX generation, feed it into Vulnetix for risk and attestation.
No migration, no rip-and-replace. Microsoft SBOM Tool keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Microsoft SBOM Tool results in Vulnetix
Upload Microsoft SBOM Tool SPDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.