OSPOlogy Asia 2026 · Tokyo · 27 July 2026

BomLens

An open-source, one-click SBOM tool for supply-chain security and regulatory compliance.

Apache-2.0 · github.com/sktelecom/bomlens
Why it exists

A mandate with no tool

SK Telecom now requires its suppliers to submit an SBOM.

Those suppliers — often with no security team — had no simple way to make one.

BomLens is that tool. Everything else follows from this one fact.

What it is

Local-first. One image. Every input.

  • No account, no server — nothing you scan is uploaded.
  • One Docker image → 7 scan modes — source, containers, binaries, firmware, received SBOMs, AI models.
  • Three ways in — a double-click desktop app, a browser UI, the CLI.
  • Bilingual — full docs in English and Korean.

Not a governance portal · not SaaS · not a compliance verdict.

What's different

Coverage, not just a scan

One image, many ecosystems

Where cdxgen's official image finds 0 Ruby and 5 Rust components, ours finds 9 and 180. Real builds, not manifest parsing — exact transitive versions, lockfile or not.

Generation, then risk

Notice, security report, risk report and conformance — all in one run.

▶ LIVELive demo · 1 of 6

One folder → a full SBOM

A Java/Maven project folder, in the desktop app. No command line. SBOM, open-source notice and security report in a single run.

Open the desktop app · pick the project folder

▶ LIVELive demo · 2 of 6

What the scan tells you

Components. Vulnerabilities with EPSS and CISA KEV. Licenses classified by copyleft strength.

Overview → Components → Dependencies → Vulnerabilities → Licenses

EPSS — Exploit Prediction Scoring System · CISA KEV — the U.S. CISA Known Exploited Vulnerabilities catalog

▶ LIVELive demo · 3 of 6

14 lines in, 39 components out

A public repo pins 14 direct dependencies — no lockfile, no local checkout. A real install inside the container surfaces 39 components, transitive versions exact.

same app · paste a Git URL · 39 components

Where this lands

The rules are arriving now

Checked today
  • SBOM minimum elements EU CRA (BSI TR-03183-2) & US NTIA fields · PURL & dependency coverage · live in demo 4
  • G7 minimum elements for AI 51 checks · 41 automated, 10 for human review
  • EU AI Act — Annex IV crosswalk obligations from 2 Aug 2026 · 23 elements mapped
  • Korea AI Framework Act — Articles 31–35 in force since 22 Jan 2026

A regulation lands on a customer; the customer passes it to its suppliers as "send us an SBOM." So the next two demos check an SBOM against exactly these rules — it makes gaps visible, it does not certify compliance.

▶ LIVELive demo · 4 of 6

Validate what a supplier sent

Two SBOMs a supplier might send. One in SPDX fails the minimum elements — no version, PURLs on 25%, no dependency graph. One in CycloneDX passes — yet carries 6 critical known-exploitable vulnerabilities. Completeness isn't safety.

Upload SPDX → the gaps · upload CycloneDX → the CVEs

▶ LIVELive demo · 5 of 6

Can you use this AI model?

Two HuggingFace models, from an AI team's seat. One is clean. The other — CC-BY-NC, pickle-format — BomLens flags caution before you build on it. Each becomes a CycloneDX ML-BOM checked against the G7 minimum elements and the EU AI Act.

EU AI Act obligations start 2 August 2026. A preparation aid — not a compliance certificate.

How it fits

Generate locally, govern centrally

BomLens On your machine · local-first Source · container image · firmware · received SBOM · AI model → generate SBOM + assess risk No account · no server standard CycloneDX TRUSCA Governance portal · a separate project Ingests SBOMs across suppliers Components · Vulnerabilities · Compliance Org-wide policy & history generate & assess — local govern — org-wide
▶ LIVELive demo · 6 of 6

Close the loop: hand it to governance

Local-first is deliberate — but one laptop can't govern a whole supply chain. BomLens emits standard CycloneDX, so the SBOM flows into any portal that reads it — here, TRUSCA by TrustedOSS.

Upload the demo-1 SBOM to TRUSCA · read it back

Full circle

The mandate, now with a tool

A regulation lands on a customer. The customer turns it into "send us an SBOM." That request reaches a supplier with no tooling — which is exactly where we started.

The difference now is the tool. Your source never leaves the laptop; the standard SBOM is the one thing built to travel onward.

It makes gaps visible — it does not certify compliance.

Try it

Your first SBOM, no command line

Download the desktop app, double-click, and scan — it checks Docker, pulls the image, and opens the UI. No console.

Prefer the command line? docker pull ghcr.io/sktelecom/bomlens:latest

Thank you

Questions?

github.com/sktelecom/bomlens
BomLens · SBOM for supply-chain security 1 / 15
← → move · f full · o overview