Generate SBOMs, scan CVEs, and check license compliance in VS Code.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "sbomapp-mcp-server" yet — see the docs or source repo.
Generate an SBOM for the current repository and list components, versions, and licenses.
An SBOM for the current project with dependencies and their basic details.
Scan the current project's dependencies for CVEs and list the results by severity.
A summary of known vulnerabilities found in dependencies, grouped by severity.
Check license compliance for the current project's dependencies and flag licenses that need attention.
A license compliance report highlighting potential compliance risks.
While coding or maintaining a project in VS Code, developers can use natural language to generate an SBOM and scan for CVEs to quickly assess dependency risk.
Before releasing software, teams can review dependency licenses to identify compliance issues that may affect delivery or distribution.
Developers using GitHub Copilot can perform SBOM, vulnerability, and license checks in VS Code through natural language, reducing tool switching.
It is an MCP server that works in VS Code with GitHub Copilot to generate SBOMs, scan for CVEs, and check license compliance through natural language.
The provided information shows that it is used in VS Code through GitHub Copilot. Other prerequisites or configuration details are not provided; see the source repository.
The current material does not provide installation steps or runtime requirements. Please see the source repository for setup details.
Scan code and infrastructure files for security vulnerabilities through MCP.
Securely access signed build conformance reports and SPDX SBOM supply chain data.
Scan code for security risks before commits with automated review assistance.
Generate and audit AI BOMs for model supply chain compliance.
Connect AI coding tools to VibeCompass projects for context and decision tracking.
Search, compare, and validate SPDX licenses, exceptions, expressions, and SBOMs.