Skip to main content

SBOM Validator Online

Validate CycloneDX and SPDX SBOM files online before release, customer delivery, or CI/CD automation. Check schema compliance, required fields, Package URLs, licenses, and common best-practice issues in one workflow.

Use it for: CycloneDX validation, SPDX validation, generated SBOM review, and quick checks before sharing an inventory.

Checks include: schema validity, required fields, Package URLs, license identifiers, format detection, and best-practice warnings.

Typical workflow: generate -> validate -> fix errors -> convert if needed -> publish.

Quick Start

  1. Paste or upload your CycloneDX or SPDX file.
  2. Leave format on Auto-detect unless you are debugging a specific format.
  3. Start with strict validation and best-practice checks enabled.
  4. Review errors first, then warnings.

SBOM Format

📄

Drag and drop your SBOM file here

or click to select a file

Validation Options

What This SBOM Validator Checks

Schema and Structure

Checks whether the SBOM is valid JSON, XML, RDF, Tag-Value, YAML, or JSON-LD for the selected CycloneDX or SPDX family.

Required Fields

Flags missing metadata, component names, versions, relationships, and other required fields that downstream tools often reject.

Package Identity

Reviews Package URLs, license identifiers, and component metadata so generated inventories are easier to match during security review.

Warnings vs Errors

Use errors for release-blocking format problems and warnings for quality issues that may still matter before customer delivery or CI/CD automation.

Which SBOM Validator Should You Use?

CycloneDX Validator

Choose CycloneDX when your SBOM comes from Syft, CycloneDX CLI, Maven, npm, Gradle, or another security-oriented generator.

SPDX Validator

Choose SPDX when your inventory is used for license review, open source disclosure, procurement, or SPDX tooling workflows.

Auto-Detect

Use auto-detect when you are unsure of the SBOM family or want to check pasted content quickly before debugging format-specific issues.

After Validation

Fix errors first, review warnings second, then use the SBOM Converter if a customer needs the file in another format.

Example SBOMs

Try validating these example files to see how an online CycloneDX or SPDX validator reports valid documents and common errors:

CycloneDX Example

A simple CycloneDX SBOM for a Node.js application

SPDX Example

An SPDX SBOM with package information and relationships

Invalid SBOM

Example with validation errors to demonstrate error reporting

Validation Help

Common Errors

  • Missing required fields: Ensure all mandatory fields are present
  • Invalid format: Check JSON/XML syntax and structure
  • Schema violations: Verify against official schemas
  • Invalid PURLs: Package URLs must follow correct format

Best Practices

  • Include component licenses and copyright information
  • Use standardized license identifiers (SPDX License List)
  • Provide accurate version information
  • Include dependency relationships where applicable