Five routes to an inventory
| Tool category | Best starting point | Critical limitation to test |
|---|---|---|
| Native build or package tooling | Resolved dependency information in a known ecosystem | Bundled files, static code and non-package content. |
| SCA-derived output | Existing component and license analysis | Export completeness and supplier ingestion are separate capabilities. |
| Dedicated generator | Repeatable artifact inventory in automation | Supported catalogs, graph meaning and private software. |
| Binary analysis | Delivered software with limited source access | Confidence, ambiguous versions and embedded libraries. |
| Platform generation | Central policy and release workflows | Coverage differences among integrated generators. |
Do not buy a platform solely because you need a JSON export. Conversely, a command-line generator does not automatically provide supplier portals, retention, access controls or incident workflow. Define the operational gap first.
Documented starting points, without rankings
| Project | Documented purpose | Useful buyer test |
|---|---|---|
| Syft | Container and filesystem SBOM generation; SPDX and CycloneDX outputs | Inspect the final image and compare packaged contents with the inventory. |
| cdxgen | CycloneDX generation across supported source/package ecosystems and container inputs | Generate from your private dependency-resolution environment. |
| OWASP Dependency-Track | CycloneDX BOM consumption and component analysis | Ingest a generator output and map it to a product version. |
Source: Syft · Official project documentation.
Source: cdxgen · Official project documentation.
Source: OWASP Dependency-Track · Official project.
These are examples of different functions, not interchangeable products or an exhaustive vendor list. Features, catalog support and format versions change. Inspect the current project documentation and pin the tested release.
Build a reference corpus
Select at least one application for each important language and packaging pattern. Include a container with OS packages, a vendored library, a transitive dependency, a private component and a deliberately unknown version. For firmware, include a statically linked library whose identity you can independently verify.
Record a reference manifest from build records, package resolution and manual inspection. Keep expected scope explicit. A runtime dependency that the generator cannot see may require another evidence source; a build-only tool may belong in a separate context rather than the shipped inventory.
Measure the useful outcomes
| Measure | Interpretation |
|---|---|
| Expected-component detection | Which reference components are found within the stated scope? |
| Identity and version correctness | How many findings can be resolved without guessing? |
| Relationship preservation | Can the consumer reconstruct the expected dependency paths? |
| Uncertainty handling | Does the output distinguish unknowns from confident findings? |
| Reproducibility | Do repeat runs against the same artifact produce equivalent inventories? |
| Operational cost | What are runtime, memory, network and maintenance requirements? |
Do not reduce the pilot to one headline score. An extra component with weak evidence can increase triage costs. A missed critical transitive component can invalidate your incident-response use case even when most packages are found.
Test automation and failure behavior
- Run without interactive prompts and with least-privilege registry credentials.
- Test private registries, proxy restrictions and air-gapped inputs if applicable.
- Distinguish scan failure from a legitimately empty inventory.
- Capture deterministic exit codes, actionable errors and output artifacts.
- Check whether collection uploads code or inventory to a hosted service.
- Review maintenance cadence, license terms and the update path for catalogs.
Keep a tested fallback version. A schema-version upgrade can break a receiving platform even when the generator itself succeeds. Put format compatibility in the release check, alongside generator execution.
When to add a management platform
Add centralized management when ownership, supplier intake, historical release queries, policy or access controls cannot be handled reliably in existing tooling. First prove one generator-to-consumer path. Buying central software before defining inventory boundaries can multiply poor-quality data.
Use the software-selection guide to evaluate those functions independently. Preserve raw artifacts so another generator or platform can be introduced later without losing the original evidence.
Primary sources
- Syft · Official project documentationTool documentation
- cdxgen · Official project documentationTool documentation
- OWASP Dependency-Track · Official projectTool documentation