Documentation menu

Getting started

Getting started

From sign-in to your first vulnerability report in about five minutes.

boring.tools takes the SBOMs your builds already produce, matches every component against the OSV vulnerability database, and keeps watching them as new advisories are published. You triage what affects you and export the result as OpenVEX.

1. Sign in

Open my.boring.tools and enter your work email. We send you a sign-in link; there are no passwords.

On your first sign-in a short onboarding asks for your name, creates your organization and lets you invite teammates. You can skip the invitations and do them later under Organizations.

2. Create a project

A project is one product or repository you want to monitor. Go to Projects → Create project, give it a name and, optionally, a description. Versions and artifacts inside the project are created automatically from your uploads — see Projects, versions and artifacts.

3. Upload an SBOM

Open the project, go to the Integration tab and drop a CycloneDX or SPDX JSON file onto Upload manually. Don’t have an SBOM yet? For an npm project:

npx @cyclonedx/cyclonedx-npm --output-file sbom.json

Uploading SBOMs lists generators for other ecosystems.

4. Read the findings

Import and analysis run in the background and usually finish within seconds. The project Overview then shows the component count, how many components we found in the vulnerability catalog and the open vulnerabilities by severity. The Findings tab lists every vulnerable component with its severity, the advisory and whether it is a direct or transitive dependency.

5. Automate it

Manual uploads are fine for a first look. To keep the data current, upload from your CI pipeline on every build of a release — see CI integration. From then on, boring.tools re-checks the versions you still support on its own whenever the vulnerability database changes.

What’s next