boring.tools takes the SBOMs your builds already produce, matches every component against the OSV vulnerability database, and keeps watching them as new advisories are published. You triage what affects you and export the result as OpenVEX.
1. Sign in
Open my.boring.tools and enter your work email. We send you a sign-in link; there are no passwords.
On your first sign-in a short onboarding asks for your name, creates your organization and lets you invite teammates. You can skip the invitations and do them later under Organizations.
2. Create a project
A project is one product or repository you want to monitor. Go to Projects → Create project, give it a name and, optionally, a description. Versions and artifacts inside the project are created automatically from your uploads — see Projects, versions and artifacts.
3. Upload an SBOM
Open the project, go to the Integration tab and drop a CycloneDX or SPDX JSON file onto Upload manually. Don’t have an SBOM yet? For an npm project:
npx @cyclonedx/cyclonedx-npm --output-file sbom.json
Uploading SBOMs lists generators for other ecosystems.
4. Read the findings
Import and analysis run in the background and usually finish within seconds. The project Overview then shows the component count, how many components we found in the vulnerability catalog and the open vulnerabilities by severity. The Findings tab lists every vulnerable component with its severity, the advisory and whether it is a direct or transitive dependency.
5. Automate it
Manual uploads are fine for a first look. To keep the data current, upload from your CI pipeline on every build of a release — see CI integration. From then on, boring.tools re-checks the versions you still support on its own whenever the vulnerability database changes.
What’s next
- Triage and VEX — record which findings affect you and why.
- Vulnerability monitoring — how matching and re-analysis work.
- AI triage — let an AI propose triage decisions for you to review.