Open source

Support Bomly

Bomly is an open-source project focused on software supply-chain visibility, SBOM analysis, and dependency risk review.

If Bomly helps your workflow, there are several simple ways to support the project.

Star the project

Starring the repository helps more developers discover Bomly and gives the project more visibility.

Star Bomly on GitHub

Share feedback

Feedback is one of the most valuable ways to support an early open-source project. If something is confusing, missing, broken, or useful, please start a discussion and let us know.

Start a discussion

Report bugs

Bug reports help improve Bomly for everyone. When reporting an issue, please include the command you ran, the ecosystem involved, the expected behavior, and the actual result.

Report a bug

Improve documentation

Documentation issues help make Bomly easier to use. If a page is missing, confusing, stale, or incorrect, please point it out.

Report a docs issue

Suggest improvements

Feature requests, workflow ideas, and documentation suggestions are welcome. Bomly is still evolving, and real-world feedback helps shape the project.

Suggest an improvement

Report security issues

Security reports should be shared through the repository security policy so they can be handled privately and responsibly.

Read security policy

Contribute

Pull requests are welcome for bug fixes, documentation improvements, tests, examples, and small enhancements. Before starting larger changes, please open an issue first so the direction can be discussed.

Read contributing guide

Sponsor development

If you find Bomly useful and want to support ongoing open-source maintenance, you can sponsor the project through GitHub Sponsors.

Sponsorship is completely optional. Contributions, feedback, bug reports, and sharing the project are also valuable ways to help.

Support on GitHub Sponsors

Thank you

Bomly is early, and every star, issue, pull request, suggestion, and sponsorship helps.

Looking for the source? Visit bomly-dev/bomly-cli.