Blog
Announcements, case studies, and technical posts from the Bomly project.
Featured
Why I built yet another dependency graph scanner
I know, another dependency scanner. But Bomly bets on a combination: one free, extensible dependency graph powering SBOMs, audits, diffs, explains, and AI agents.
Read
Announcing Bomly
A free, open-source CLI and GitHub Action for dependency diffs, SBOMs, vulnerability and license audits, and explaining why packages are present in your builds.
Read
How we strengthened Bomly CLI's quality and security
Bomly CLI v0.21.0 strengthens dependency graphs, safety boundaries, cross-platform tests, and public evidence. Here is what users gain from this work.
Read
Scanning a polyglot monorepo with Bomly
Scan npm workspaces, Go modules, and Python services in one pass: Bomly CLI's recursive discovery, per-module manifests, and CI artifacts on a real monorepo.
Read
A coding agent fixed only 14% of vulnerable advisories. Bomly MCP set a 98% floor.
On a 13-module Maven project, Bomly MCP removed Claude Code's catastrophic misses and made Codex CLI about 1.7× faster. Smaller apps did fine without it.
Read
Make Your Coding Agent Dependency-Aware
Connect Bomly's MCP server to Claude Code, Cursor, or VS Code so your coding agent can scan, explain, and diff dependency changes from inside the repo.
Read
Why Is This Dependency Here?
Use Bomly CLI to trace why a package is in your dependency graph, then add license, vulnerability, and Scorecard context for review.
Read
Why I built yet another dependency graph scanner
I know, another dependency scanner. But Bomly bets on a combination: one free, extensible dependency graph powering SBOMs, audits, diffs, explains, and AI agents.
Read
Announcing Bomly
A free, open-source CLI and GitHub Action for dependency diffs, SBOMs, vulnerability and license audits, and explaining why packages are present in your builds.
Read