
Dependquarry: SBOM Review
Read CycloneDX & SPDX
0 ratings
$2.99
Rating summary
About
Dependquarry is a private software-bill-of-materials review bench for developers, maintainers, auditors, consultants, and small security teams who need a human-readable decision layer without uploading product composition.
Turn machine-oriented SBOM records into an offline, accountable component review with explicit evidence gaps.
KEY FEATURES
- CycloneDX and SPDX JSON import
- Component and evidence register
- Severity and dependency-depth screen
- Package URL and provenance notes
- Reachability and disposition workflow
- License evidence tracking
- Portable component decision artifact
- No source-code or SBOM upload
- Native structured-file or CSV import
- Local PDF, workspace JSON, and domain-artifact export
- No account, ads, analytics, tracking, IAP, or subscription
Dependquarry interprets imported component metadata and user-entered findings; it does not fetch advisories, prove exploitability, determine legal obligations, or certify a product. Verify package identity, versions, reachability, licenses, provenance, and current advisories with accountable experts.
Show more
What's New in Dependquarry
1.1
August 31, 2026
Removes roughly 39 MB of image files that were bundled but never opened by any screen. SBOM parsing and the review checklist behave exactly as before.



