bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Documentation
Analyze Your Software DNA.
Bomly is a free, open-source CLI for dependency intelligence. It scans source trees, SBOMs, Git refs, and container images; explains why dependencies are present; enriches packages with vulnerability and license data when you ask for it; evaluates policy; and writes automation-friendly output for CI.
Free and open source, no account, no login. One binary. No service to host. No telemetry. No outbound matcher calls unless you opt in with `--enrich`. Network and Privacy documents every network trigger so you can audit that claim instead of taking it on faith.
Install Bomly
# macOS / Linuxbrew
brew install bomly-dev/tap/bomly
# Linux / macOS install script
curl -fsSL https://bomly.dev/install.sh | sh
# Windows
winget install Bomly.BomlyCLIPrebuilt archives and Linux packages are published from GitHub Releases. Releases include `bomly` (full binary with builtin Syft and Grype) and `bomly-lite` (smaller binary that shells out to external `syft` and `grype`).
Verify the install:
bomly versionFor Linux packages, Scoop, Go install, checksums, pinned versions, upgrades, and uninstall instructions, see Installation.
Start With a Scan
# Scan the current project
bomly scan
# Scan a specific directory
bomly scan --path ./services/api
# Scan a container image
bomly scan --image ghcr.io/example/app:latest
# Scan a remote Git ref
bomly scan --url https://github.com/owner/repo --ref v1.2.3
# Read an existing SPDX or CycloneDX SBOM
bomly scan --sbom --path ./sbom.cdx.jsonBomly reads manifests, lockfiles, package-manager output, container layers, or existing SBOMs and turns them into one dependency graph. Native detectors cover Go, npm, pnpm, Yarn, Maven, Gradle, Python, Composer, Bundler, GitHub Actions, SBOM ingest, and more. Syft fills the long tail, including container images. See the Support Matrix and Scan Targets.
What Bomly Can Answer
| Question | Command |
|---|---|
| What do we depend on? | `bomly scan` |
| What changed in this PR or branch? | `bomly diff --base main --head HEAD` |
| Why is this package here? | `bomly explain lodash` |
| Which findings matter to policy? | `bomly scan --enrich --audit --fail-on high` |
| Can CI fail on high-severity findings? | `bomly scan --enrich --audit --fail-on high --format sarif` |
| Can I triage reachable findings first? | `bomly scan --enrich --audit --analyze --fail-on high --fail-on reachable` |
For more recipes, see Getting Started and
Use Cases. To review the public inputs, commands, expected
results, and limitations behind important behavior claims, see
Explore Interactively
Open the terminal UI when you want to inspect a graph by hand:
bomly scan --interactiveUse it to fuzzy-find packages, inspect versions and scopes, pivot through findings, and see how a dependency entered the graph without writing a report to disk. See Interactive TUI.
Enrich and Audit
By default, Bomly does not call vulnerability, license, lifecycle, or scorecard services. Add `--enrich` when you want external package intelligence:
# Fetch vulnerability and license data
bomly scan --enrich
# Evaluate policy against enriched package data
bomly scan --enrich --audit --fail-on high
# Add experimental reachability analysis
bomly scan --enrich --audit --analyze --fail-on high --fail-on reachableBuilt-in enrichment uses public services such as OSV, CISA KEV, deps.dev, and OpenSSF Scorecard. `--audit` evaluates the vulnerability and license data already present on packages; use `--enrich --audit` when you want to fetch and evaluate in one run.
Reachability is experimental. It is useful for triage, but "unreachable" is not a guarantee of safety. Read Reachability before using `--fail-on reachable` as a CI gate.
Explain and Diff
Use `explain` when a transitive package shows up and you need the path:
bomly explain requests
bomly explain lodash --path ./webUse `diff` when you need to review dependency changes across Git refs or SBOMs:
# Compare Git refs
bomly diff --base main --head HEAD
# Compare two SBOM files
bomly diff --sbom --base ./old.spdx.json --head ./new.spdx.jsonSee Getting Started for the first-run walkthrough and Use Cases for PR review, upgrade review, and incident triage recipes.
Generate Output for CI
Bomly can write human-readable text, JSON, SARIF, SPDX 2.3, and CycloneDX 1.7:
# Structured JSON for automation
bomly scan --json
# SARIF for security tabs and code-scanning integrations
bomly scan --enrich --audit --fail-on high --format sarif
# Write SBOM artifacts (add --format text to also print the report)
bomly scan -o spdx=sbom.spdx.json -o cyclonedx=sbom.cdx.json
# Emit one SBOM to stdout
bomly scan --format cyclonedxExit codes are stable for scripts: `0` for clean results, `2` for policy violations, and separate values for usage, runtime, and no-supported-project failures. See Output Formats, SBOM Formats, and Exit Codes.
To gate pull requests, use the Bomly Guard action or call the CLI directly from your workflow:
# .github/workflows/bomly.yml
- uses: actions/checkout@v5
with:
fetch-depth: 0
- uses: bomly-dev/bomly-guard@v1
with:
fail-on: highSee Bomly Guard and CI Integration.
Use Bomly With AI Agents
Bomly can run as a local MCP server so AI agents can call the same dependency graph tools you use on the command line:
bomly mcp serveIf you have not installed the CLI, the `bomly-mcp` npm wrapper starts the same server:
npx -y bomly-mcpAdd Bomly to an MCP-aware agent such as Claude Code, Cursor, VS Code, or a custom tool, and the agent receives structured JSON it can summarize or reason over. See MCP Server for setup recipes and the tool reference.
Configure and Extend
Bomly reads configuration from your user config, an explicitly selected
config file, `BOMLY_*` environment variables, and CLI flags, with later
sources taking precedence:
1. `~/.bomly/config.yaml`
2. `--config ` or `BOMLY_CONFIG`
3. `BOMLY_*` environment variables
4. CLI flags
Repository config files are never loaded automatically. A project may keep
its shared configuration at `.bomly/config.yaml`, but you must trust it
explicitly with `--config .bomly/config.yaml` or `BOMLY_CONFIG`. See the
generated Config Reference.
Managed plugins let you add detectors, matchers, and auditors without forking Bomly:
bomly plugins install github:bomly-dev/bomly-plugin-bun-lock-detector@v0.1.0
bomly plugins enable bomly.examples.detector.bun-lock
bomly plugins verify bomly.examples.detector.bun-lockSee Plugins for install, trust, and authoring guidance.
Documentation
- Getting Started - install Bomly and run your first scan
- Tutorial - from first scan to a CI gate on a real project
- FAQ - quick answers on privacy, accounts, and tool differences
- Installation - install methods, checksums, upgrades, uninstall
- Use Cases - practical recipes for PR gates, SBOMs, triage, and offline scans
- Scan Targets - directories, Git repos, containers, and SBOMs
- Output Formats - text, JSON, SARIF, SPDX, CycloneDX
- SBOM Formats - SPDX 2.3 and CycloneDX 1.7, ingest, and conversion recipes
- CI Integration - GitHub Actions, GitLab, Jenkins, Azure, CircleCI
- Bomly Guard - turnkey GitHub Action for PR dependency review
- MCP Server - connect Bomly to Claude Code, Cursor, VS Code, or another MCP client
- Reachability - experimental reachable-vulnerability triage
- Plugins - managed external detectors, matchers, and auditors
- Release Notes - what changed in each version
- All Documentation - full docs index
Contributor setup lives in CONTRIBUTING.md. Architecture details live in docs/ARCHITECTURE.md.
Questions
For questions, ideas, and general support, please use Bomly Discussions.
Use this repository's issues only for confirmed bugs, regressions, or actionable implementation work.
Support
Bomly is an open-source project. If you find it useful, you can support the project by starring the repository, sharing feedback, opening issues, contributing improvements, or sponsoring ongoing maintenance.
See Support Bomly.
License
Bomly CLI is licensed under the Apache License 2.0.
Frequently asked questions
What is bomly-cli?
bomly-cli is Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
How do I install bomly-cli?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is bomly-cli open source?
Yes — it is hosted on GitHub at https://github.com/bomly-dev/bomly-cli and has 11 stars.
Related MCP tools
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
The missing open-source Kubernetes UI with a built-in MCP server for AI agents. See what's broken, why, and what changed. Issues, Topology, event timeline, Helm, GitOps, live service traffic, and cluster audits - all in one Go binary.
mcp-language-server gives MCP enabled clients access semantic tools like get definition, references, rename, and diagnostics.
One place to manage & connect to all your MCP servers
eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
ToolHive makes deploying MCP servers easy, secure and fun Go-based implementation. Trusted by 1300+ developers. Trusted by 1300+ developers.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP