Skip to content

SBOM

Generate signed Software Bills of Materials from the dependencies in your repositories.

How it works

OpenHack uses repository dependency data to generate a Software Bill of Materials for an application or service. The artifact records the packages and versions that make up the software, including transitive dependencies resolved from project lockfiles.

Generated SBOMs are signed and can be refreshed as dependencies change, giving engineering, security, and compliance teams a consistent component inventory for reviews and audit workflows.

Find the hardest vulnerabilities

OpenHack reads your code like a real security engineer using AI - tracing through routes, authentication, business logic and entrypoints together. It finds vulnerabilities that traditional pattern scanners miss - IDORs, broken access control, auth bypasses, race conditions and more.

No slop, just verified vulnerabilities

Vulnerabilities are verified in your environment. All OpenHack vulnerabilities come with a business impact, proof of concept and recommended fixes.

AI Autofixes

Fix issues in just one click using AI Autofixes.

Integrate with your stack

Review fixes in GitHub, ask questions in Slack, and assign work in Linear. Security stays in the tools your team already uses to ship.

What it covers

Packages and versions

Record the component names and resolved versions found in the repository's dependency sources.

Dependency relationships

Represent direct and transitive components so reviewers can understand how a package enters the application.

Repository context

Associate the generated inventory with the application or service from which it was created.

Inventory changes

Reflect additions, removals, and version updates when a new SBOM is generated from the repository.

What you get

  • A signed Software Bill of Materials
  • Direct and transitive package inventory
  • Resolved versions and dependency relationships
  • An artifact for security and compliance reviews

Put your AI security engineer to work.

Connect a repository to the managed platform to generate a signed component inventory and keep it aligned with dependency changes.