Inspect package identifiers, lockfiles, dependency choices and release or container text using caller-supplied evidence.
How to choose
Choose the operation matching the supplied manifest or metadata format. Version selection uses declared candidates; risk flags reflect explicit evidence rather than a live vulnerability database.
No package installation, registry lookup, CVE scan, image execution or legal license determination.
Extract names, versions, PURLs, declared licenses and hashes from CycloneDX JSON 1.5/1.6 or SPDX JSON 2.3. Includes nested CycloneDX components and metadata.component; excludes services, external BOMs, relationships and unconsumed fields. No full document, license, PURL or hash validation.
Choose for: Build a small auditable component inventory from caller-supplied SBOM JSON Retain source JSON pointers and distinguish declared/concluded license fields
Outside this profile: Full SBOM conformance checks, dependency resolution or vulnerability scanning XML/tag-value inputs, external document traversal or artifact verification
Compare two supported SBOMs by unique exact group/name (default) or versionless generic-PURL identity. Report added/removed components and version/license/hash/PURL/type changes. Duplicate identities are rejected rather than cross-paired. Reference IDs and source positions are ignored; license comparison is textual, not semantic.
Choose for: Review deterministic component changes between two caller-supplied SBOMs Reject ambiguous duplicates instead of inventing version matches
Outside this profile: License equivalence, transitive graph impact or vulnerability analysis Inventing matches across renamed packages, ecosystems or duplicate identities
Extract npm package-lock v2/v3 packages by sorted location, retaining versions, resolved sources, integrity/license strings and dev/optional/devOptional/link/install-script flags. No package installation, graph resolution or hash verification. Workspace names require a declared name; node_modules names can be inferred from location.
Choose for: Read package locations and declared metadata without installing anything Retain nested copies and workspace links as separate locations
Outside this profile: npm v1, Yarn, pnpm, Poetry or Cargo lockfiles Transitive dependency graph resolution, artifact retrieval or installation verification
Flag declared npm-style metadata gaps: missing/non-exact canonical SemVer pins, missing/insecure/local/unrecognized sources, missing/malformed or SHA1-only integrity, and missing license markers. Syntax/presence heuristics only; no vulnerability database, artifact verification, trust score or legal conclusion.
Choose for: Triage a bounded declared dependency list before human policy review Find missing pins, source declarations, integrity strings and license metadata
Outside this profile: Vulnerability or malware scanning, security certification, license compatibility decisions Treating absent flags as evidence a dependency is safe or authentic
Parse bounded SPDX-style license expression syntax into a flat indexed AST, unique identifiers/exceptions and fully parenthesized normalization. Supports AND/OR/WITH, +, LicenseRef and DocumentRef; enforces precedence and simple-left WITH. Does not validate current license/exception lists or give compliance advice; NONE/NOASSERTION document markers are rejected.
Choose for: Inspect operator precedence and identifier references in a supplied expression Perform bounded syntax preparation before a separate policy or license-list check
Outside this profile: Proving identifiers are in the current SPDX list License compatibility, legal advice or boolean expansion of all license choices
Inspect one supplied Dockerfile for 14 bounded static risk and hygiene signals with line ranges, rule IDs, redacted evidence and remediation. Understands continuations, escape directives, literal stage inheritance and JSON forms. No execution, image/CVE scan, fetch, variable evaluation or safe-image verdict; heredocs, ONBUILD and custom frontends are rejected.
Choose for: Get bounded static observations about one supplied Dockerfile's literal image references, stage/user configuration, COPY/ADD sources, secret-like names and instruction forms.
Outside this profile: Build or execute a Dockerfile, inspect an image or registry, find CVEs, certify security, analyze Compose/Kubernetes, evaluate shell commands or ARG values, or parse heredocs, ONBUILD or custom syntax frontends.