Sbomx
БесплатноНе проверенGenerates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.
Описание
Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.
README
SBOMX
Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.
PyPI CI License: COCL 1.0 Suite
Application & Mobile Security — SAST/DAST-lite and binary triage.
pip install cognis-sbomx
sbomx scan . # → prioritized findings in seconds
🔎 Example output
Real, reproducible output from the tool — runs offline:
$ sbomx-emit --version
sbomx 0.2.4
$ sbomx-emit --help
usage: sbomx [-h] [--version] {scan,db,feeds} ...
Generate a CycloneDX SBOM for mobile apps and match bundled libraries against vulnerability and privacy-tracker databases.
positional arguments:
{scan,db,feeds}
scan scan an .apk/.ipa/zip or directory and produce an SBOM +
findings
db query the bundled offline 262k-record OSV vulnerability
database
feeds manage the bundled edge/air-gap vulnerability data feeds
options:
-h, --help show this help message and exit
--version show program's version number and exit
Command-line interface for SBOMX.
Examples
--------
# Generate a CycloneDX SBOM (JSON) for an APK and write it to a file
sbomx scan app.apk --format json -o app.cdx.json
# Human-readable findings table; exit non-zero if vulns/trackers found
sbomx scan app.ipa --format table
# Scan an extracted bundle directory and fail CI on HIGH severity vulns
sbomx scan ./unpacked_app --fail-on high
# Use a manifest mapping lib->version to refine version-unknown components
sbomx scan app.apk --manifest versions.json
Exit codes
----------
0 clean (no findings, or findings below --fail-on threshold)
1 findings at/above the fail threshold (default: any tracker or vuln)
2 usage / runtime error
Blocks above are real
sbomxoutput — reproduce them from a clone.
Sample result format (illustrative values — run on your own data for real findings):
{
"sbomx": {
"platform": "stix",
"findings": [
{
"uuid": "12345678-1234-5678-1234-567812345678",
"vulnerability": {
"name": "CVE-2023-12345"
},
"severity": "high",
"description": "A high-severity vulnerability in the application."
}
]
}
}
Usage — step by step
sbomx generates a CycloneDX SBOM for mobile apps and matches bundled libraries against vulnerability and privacy-tracker databases. Console script: sbomx.
- Install:
pipx install sbomx # or: pip install sbomx - Scan an app bundle (
.apk/.ipa/.zip) or an extracted directory and print a findings table:
Exitsbomx scan app.apk --format table1= findings at/above the--fail-onthreshold (default: any finding),0= clean,2= error. - Emit a CycloneDX 1.5 SBOM as JSON to a file (also
--format sariffor GitHub code-scanning, or--format csvfor spreadsheets/ticketing):sbomx scan app.apk --format json -o app.cdx.json sbomx scan app.apk --format sarif -o app.sarif.json # upload to code-scanning sbomx scan app.apk --format csv -o findings.csv - Refine version-unknown components with a manifest mapping library key to version:
sbomx scan app.apk --manifest versions.json --format json -o app.cdx.json - Gate CI on severity — fail the build only on HIGH+ vulnerabilities/trackers:
sbomx scan ./unpacked_app --fail-on high || echo "high-severity component findings — blocking release"
Contents
- Why sbomx? · Features · Quick start · Example · Demos · Architecture · AI stack · How it compares · Integrations · Install anywhere · Related · Contributing
Why sbomx?
Syft/Grype ignore the mobile binary world; sbomx surfaces vulnerable bundled SDKs and privacy trackers inside shipped apps — perfect for app-store compliance gating.
sbomx is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.
Features
- ✅ Detects bundled libraries from APK/IPA/zip member paths and native
.so/.dylibnames - ✅ Recovers versions from filenames or a supplied
--manifest(key → version) - ✅ Matches against a curated vuln DB (CVE-style) and a privacy-tracker DB (Exodus-style)
- ✅ Live threat-feed enrichment: flags findings on CISA's Known-Exploited (KEV) list — see Live data feeds
- ✅ Four output formats:
table· CycloneDX 1.5json· SARIF 2.1.0sarif·csv - ✅ CI gate via
--fail-on {info,low,medium,high,critical,never}+ exit codes - ✅ 11 ready-to-run demos covering iOS/Android/React Native/Flutter/games + live KEV enrichment
- ✅ Runs on Linux/macOS/Windows · Docker · devcontainer
- ✅ Ports in Python, JavaScript, Go, and Rust (
ports/)
Quick start
pip install cognis-sbomx
sbomx --version
sbomx scan . # scan current project
sbomx scan . --format json # machine-readable
sbomx scan . --fail-on high # CI gate (non-zero exit)
Example
A real scan of an Android bundle that ships okhttp-4.9.0.jar, native
libssl/libwebp, Firebase + Crashlytics and the AppsFlyer SDK:
$ sbomx scan app.apk --format table
Target: app.apk
Components (7):
appsflyer ? maven pkg:maven/com.appsflyer/appsflyer
firebase-core ? maven pkg:maven/com.google.firebase/firebase-core
firebase-crashlytics ? maven pkg:maven/com.google.firebase/firebase-crashlytics
gson ? maven pkg:maven/com.google.code.gson/gson
libwebp ? native pkg:generic/libwebp
okhttp 4.9.0 maven pkg:maven/com.squareup.okhttp3/[email protected]
openssl 1.1.1k native pkg:generic/openssl
Vulnerabilities (4):
[CRITICAL] CVE-2023-4863 libwebp@?
Heap buffer overflow in WebP lossless (VP8L) decoding; exploited in the wild.
fix: upgrade to >= 1.3.2
[HIGH ] CVE-2022-0778 [email protected]
BN_mod_sqrt infinite loop (DoS) when parsing certificates.
fix: upgrade to >= 1.1.1n
[MEDIUM ] CVE-2021-0341 [email protected]
OkHttp improper certificate validation (hostname not verified).
fix: upgrade to >= 4.9.2
Trackers (3):
AppsFlyer (Analytics, Advertisement)
Google Firebase Analytics (Analytics)
Google Firebase Crashlytics (Crash reporting, Analytics)
Add --enrich-osv to cross-reference every detected component against the
bundled 262k-record offline OSV database (no network), or --enrich-kev to
flag CVEs that are actively exploited per CISA.
Demos — real-use-case scenarios
Each folder under demos/ ships a generator (make_sample.py) that
builds a realistic app bundle plus a SCENARIO.md (where the data came from,
the exact command, expected output, and how to act). All library versions are
drawn from the tool's own detection rules + vuln DB, so every demo deterministically
reproduces its documented findings.
| Demo | Scenario | Highlights |
|---|---|---|
| 01-basic | First Android scan | 3 vulns + 2 trackers, table + JSON |
| 02-clean | First-party app, no SDKs | 0 findings, exit 0 |
| 03-mixed | Mixed severities | --fail-on high vs critical gate |
| 04-ios-banking | iOS .ipa framework audit |
CocoaPods + native crypto, Realm CVE |
| 05-react-native-ecommerce | RN privacy + vuln review | 3 trackers, CSV export |
| 06-clean-release | Release candidate | all libs patched, gate passes |
| 07-manifest-resolve | Stripped build | --manifest resolves version-unknown potentials |
| 08-game-adtech | F2P game ad-SDK sweep | 5 trackers + native media CVEs |
| 09-flutter-app | Flutter native audit | 3 HIGH native CVEs |
| 10-ci-sarif-gate | CI + GitHub code-scanning | SARIF upload + HIGH gate |
python demos/04-ios-banking/make_sample.py
python -m sbomx scan demos/04-ios-banking/banking.ipa --format table
Live data feeds — edge / air-gap ingestion
sbomx enriches its findings with real, authoritative public vulnerability feeds. The killer feature: an SBOM finding is no longer "this CVE applies" but "this CVE is being exploited in the wild right now — patch it first."
| Feed id | Source (real, keyless) | Used for |
|---|---|---|
cisa-kev |
CISA Known Exploited Vulnerabilities | Flag + escalate actively-exploited CVEs to critical; surface KEV dateAdded / federal dueDate |
osv |
OSV.dev | Package+version vulnerability lookups across ecosystems |
Enrich a scan
sbomx scan app.apk --enrich-kev # online: fetch/refresh KEV, then enrich
sbomx scan app.apk --enrich-kev --offline # air-gap: use the local KEV cache only
Findings whose CVE is on the KEV list are tagged *** CISA KNOWN-EXPLOITED ***,
bumped to critical, and annotated with the authoritative dates:
[CRITICAL] CVE-2023-4863 [email protected] *** CISA KNOWN-EXPLOITED ***
Heap buffer overflow in WebP lossless (VP8L) decoding; exploited in the wild.
KEV: added 2023-09-13 patch-by 2023-10-04 ransomware=Unknown
fix: upgrade to >= 1.3.2
Manage the feeds
sbomx feeds list # the feeds this tool consumes (+ URLs)
sbomx feeds update cisa-kev # keyless HTTPS fetch -> disk cache
sbomx feeds get cisa-kev --offline # re-serve from cache, never touch network
Edge / air-gap workflow
The ingestion engine (sbomx/datafeeds.py, stdlib-only)
caches every feed to disk and re-serves it offline, so sbomx keeps working on
disconnected / classified / forward-deployed gear. Set the cache location with
COGNIS_FEEDS_CACHE (default ~/.cache/cognis-feeds).
Sneakernet into an air gap:
# on a connected host
sbomx feeds update cisa-kev
python -m sbomx.datafeeds snapshot-export feeds.tar.gz
# ... carry feeds.tar.gz across the gap ...
# on the disconnected enclave
python -m sbomx.datafeeds snapshot-import feeds.tar.gz
sbomx scan app.apk --enrich-kev --offline
See demos/11-kev-enrichment for a complete,
offline-runnable example. The test suite ships a trimmed real-data feed cache
under tests/fixtures/feeds-cache/, so CI enriches findings with zero network
access.
Architecture
flowchart LR
IN[target / manifest] --> P[sbomx<br/>checks + rules]
P --> OUT[findings (JSON / SARIF)]
Use it from any AI stack
sbomx is interoperable with every popular way of using AI:
- MCP server —
sbomx mcp(Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet) - OpenAI-compatible / JSON — pipe
sbomx scan . --format jsoninto any agent or LLM - LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
- CI / scripts — exit codes + SARIF for non-AI pipelines
How it compares
| Cognis sbomx | Syft + Grype, extended to the mobile binary (APK | |
|---|---|---|
| Self-hostable, no account | ✅ | varies |
| Single command, zero config | ✅ | ⚠️ |
| JSON + SARIF for CI | ✅ | varies |
| MCP-native (AI agents) | ✅ | ❌ |
| Polyglot ports (JS/Go/Rust) | ✅ | ❌ |
| Open license | ✅ COCL | varies |
Built in the spirit of Syft + Grype, extended to the mobile binary (APK/IPA native .so/dylib) world, re-framed the Cognis way. Missing a credit? Open a PR.
Integrations
Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (sbomx mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.
Install — every way, every platform
pip install "git+https://github.com/cognis-digital/sbomx.git" # pip (works today)
pipx install "git+https://github.com/cognis-digital/sbomx.git" # isolated CLI
uv tool install "git+https://github.com/cognis-digital/sbomx.git" # uv
pip install cognis-sbomx # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/sbomx:latest --help # Docker
brew install cognis-digital/tap/sbomx # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/sbomx/main/install.sh | sh
| Linux | macOS | Windows | Docker | Cloud |
|---|---|---|---|---|
scripts/setup-linux.sh |
scripts/setup-macos.sh |
scripts/setup-windows.ps1 |
docker run ghcr.io/cognis-digital/sbomx |
DEPLOY.md (AWS/Azure/GCP/k8s) |
Related Cognis tools
- apkpeek — One-command static triage of Android APK/AAB binaries: surfaces hardcoded secrets, exported components, dangerous permissions, and insecure manifest flags as a single SARIF report.
- ipasnitch — Static scanner for iOS .ipa bundles that flags ATS exceptions, missing entitlements hardening, embedded URLs/secrets, and weak Info.plist transport settings.
- hookcraft — Generates ready-to-run Frida instrumentation scripts from a YAML intent (e.g. 'bypass SSL pinning', 'dump crypto keys') and verifies they attach to a target process.
- dastlite — A headless, config-as-code DAST runner that crawls an authenticated web/mobile-API surface and fires a curated active-scan ruleset, emitting deduplicated SARIF.
- semsift — Lightweight semantic-aware SAST that runs curated taint rules over diffs only, so PRs get fast incremental SAST instead of whole-repo scan fatigue.
- cheatsense — Anti-cheat telemetry analyzer that ingests game session logs and flags statistically anomalous input/aim/movement signatures with explainable per-flag scoring.
Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram
Contributing
PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.
⭐ If
sbomxsaved you time, star it — it genuinely helps others find it.
Interoperability
{} composes with the 300+ tool Cognis suite — JSON in/out and a shared
OpenAI-compatible /v1 backbone. See INTEROP.md for the
suite map, composition patterns, and reference stacks.
License
Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.
Bundled vulnerability database
Ships sbomx/cognis_vulndb.jsonl.gz — 262,351 real vulnerabilities (OSV: PyPI/npm/Go/Maven/RubyGems/crates.io/NuGet) with detailed metadata (CVE/GHSA aliases, ecosystem, severity/CVSS, affected packages, dates). Pure-stdlib offline loader vulndb_local.VulnDB (count/by_cve/by_package/search), air-gap ready. Refresh/extend via datafeeds.py bulk.
Offline CycloneDX-component → CVE matching
sbomx scan ... --enrich-osv maps every detected CycloneDX component to the
package coordinate OSV uses for its ecosystem and matches it against the bundled
262k-record corpus — fully offline, no network, no key:
| Ecosystem | Component coordinate probed |
|---|---|
| Maven | pkg:maven/<group>/<artifact> → <group>:<artifact> (e.g. com.squareup.okhttp3:okhttp) |
| npm | the package name (e.g. react-native) |
| CocoaPods | the framework name (e.g. Alamofire) |
| native | the library key (e.g. openssl, sqlite, libwebp) |
OSV-sourced findings are appended to the scan result, de-duplicated against the curated VULN_DB, severity-bucketed from the record's CVSS v3 vector, and marked version-unconfirmed when the compact corpus carries no version range — so the tool never silently claims a precise match it cannot prove.
sbomx scan app.apk --enrich-osv --format json -o app.cdx.json
Query the database directly (handy for triage / CI):
sbomx db count # 262351
sbomx db cve CVE-2021-44228 # log4j → GHSA-jfh8-c2jp-5v3q
sbomx db package org.apache.logging.log4j:log4j-core # advisories for the maven coordinate
sbomx db search "buffer overflow" --limit 5
from sbomx.vulndb_local import VulnDB
db = VulnDB()
db.count() # 262351
db.by_cve("CVE-2021-44228") # [{'id': 'GHSA-jfh8-c2jp-5v3q', 'aliases': ['CVE-2021-44228'], ...}]
db.by_package("org.apache.logging.log4j:log4j-core")
Edge / air-gap refresh
The corpus is the offline baseline — the tool has 262k real vulns the moment it is cloned, with zero setup. To refresh or extend it from upstream while connected, then sneakernet into a disconnected enclave, use the stdlib-only datafeeds.py ingestion engine against the real, keyless NVD / OSV / GHSA / CISA-KEV feeds catalogued in data_feeds_2026.json:
# on a connected host: refresh feeds into the disk cache
python -m sbomx.datafeeds update osv cisa-kev
python -m sbomx.datafeeds snapshot-export feeds.tar.gz
# ... carry feeds.tar.gz across the air gap ...
# on the disconnected enclave: import + scan offline
python -m sbomx.datafeeds snapshot-import feeds.tar.gz
sbomx scan app.apk --enrich-osv --enrich-kev --offline
Установка Sbomx
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/cognis-digital/sbomxFAQ
Sbomx MCP бесплатный?
Да, Sbomx MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Sbomx?
Нет, Sbomx работает без API-ключей и переменных окружения.
Sbomx — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Sbomx в Claude Desktop, Claude Code или Cursor?
Открой Sbomx на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
GitHub
PRs, issues, code search, CI status
автор: GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
автор: mcpdotdirectCompare Sbomx with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории development
