This release is a pre-release and may not be stable for production use.
SBOM Visualization Plugin
A plugin for Surfactant that generates interactive visualizations of CyTRICS-formatted SBOMs
Installation
SBOMVis can be installed as a plugin for Surfactant or as a standalone executable with pip & pipx. Commands for installing with pipx (recommended) are shown below:
As a Surfactant plugin
$ pipx inject surfactant sbomvis
Standalone installation
$ pipx install sbomvis
Usage
The plugin can generate visualizations when running Surfactant's generate command or from an existing SBOM.
Generating visualizations during a Surfactant run
Passing in sbomvis as the output format will cause Surfactant to generate an HTML file with the same name as the SBOM containing the visualization. The original JSON SBOM will also be saved to the same directory.
$ surfactant generate --output_format=sbomvis SPECIMEN_CONFIG SBOM_OUTFILE
Generating visualizations from an existing SBOM
Visualizations can be created from an existing Surfactant SBOM by running sbomvis and passing in it's path with -p.
Surfactant SBOM Visualization
options: -h, --help show this help message and exit -p PATH [PATH ...], --path PATH [PATH ...] Path(s) to JSON SBOMs -c, --cull Enable culling of isolated nodes (may improve performance on large graphs at the cost of completeness) -pb, --use-progress-bar Display progress bar while waiting for large graphs to load instead of disabling physics
## Controls
Several controls are included:
* Clicking on a node will reveal a sidebar with more information about it
* Right clicking on a node will pin/unpin it in place
* Archives and containers can be expanded or collapsed by double clicking
Note: Physics is initially disabled for large graphs (~600+ nodes) to improve loading times. Once the graph is on screen it should be re-enabled via clicking the toggle in the upper left corner.
Metadata
Release files for sbomvis 0.0.0rc16
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sbomvis-0.0.0rc16.tar.gz | 28.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sbomvis-0.0.0rc16-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 59.1 kB
Release files / sbomvis-0.0.0rc16.tar.gz
| Download URL | sbomvis-0.0.0rc16.tar.gz |
|---|---|
| Size | 28.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ee4cba2ed5d1338d304bd5293ac8dc5ef76b49df65b816d36de4b982b93db7a7
|
|
BLAKE2b-256 checksum How to use checksums |
4ddb4e32541c4b1f3598f95015711a202d58e1a9d1db95a4757c563a34ebbd06
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Nov 15, 2025.
Transparency logRelease files / sbomvis-0.0.0rc16-py3-none-any.whl
| Download URL | sbomvis-0.0.0rc16-py3-none-any.whl |
|---|---|
| Size | 30.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9766508f43554062961b9caf3b07ea097ff81240b558b3e0a2f1af4b8d0caf11
|
|
BLAKE2b-256 checksum How to use checksums |
b2e31ab0f5f99d23c3037ac192b237e7b8d6a501fd9cd00fe3c8a6ada75e3141
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Nov 15, 2025.
Transparency log