Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

SBOM Visualization Plugin

A plugin for Surfactant that generates interactive visualizations of CyTRICS-formatted SBOMs Example Output

Installation

SBOMVis can be installed as a plugin for Surfactant or as a standalone executable with pip & pipx. Commands for installing with pipx (recommended) are shown below:

As a Surfactant plugin

$ pipx inject surfactant sbomvis

Standalone installation

$ pipx install sbomvis

Usage

The plugin can generate visualizations when running Surfactant's generate command or from an existing SBOM.

Generating visualizations during a Surfactant run

Passing in sbomvis as the output format will cause Surfactant to generate an HTML file with the same name as the SBOM containing the visualization. The original JSON SBOM will also be saved to the same directory.

$ surfactant generate --output_format=sbomvis SPECIMEN_CONFIG SBOM_OUTFILE

Generating visualizations from an existing SBOM

Visualizations can be created from an existing Surfactant SBOM by running sbomvis and passing in it's path with -p.

Surfactant SBOM Visualization

options: -h, --help show this help message and exit -p PATH [PATH ...], --path PATH [PATH ...] Path(s) to JSON SBOMs -c, --cull Enable culling of isolated nodes (may improve performance on large graphs at the cost of completeness) -pb, --use-progress-bar Display progress bar while waiting for large graphs to load instead of disabling physics


## Controls
Several controls are included:
* Clicking on a node will reveal a sidebar with more information about it
* Right clicking on a node will pin/unpin it in place
* Archives and containers can be expanded or collapsed by double clicking

Note: Physics is initially disabled for large graphs (~600+ nodes) to improve loading times. Once the graph is on screen it should be re-enabled via clicking the toggle in the upper left corner.

Metadata

Release files for sbomvis 0.0.0rc16

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sbomvis 0.0.0rc16
File Size Uploaded
sbomvis-0.0.0rc16.tar.gz 28.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sbomvis 0.0.0rc16
File Interpreter ABI Platform
sbomvis-0.0.0rc16-py3-none-any.whl Python 3 none any Details

Total release size: 59.1 kB

Release files / sbomvis-0.0.0rc16.tar.gz

Download URL sbomvis-0.0.0rc16.tar.gz
Size 28.5 kB
Tags Source
SHA-256 checksum
How to use checksums
ee4cba2ed5d1338d304bd5293ac8dc5ef76b49df65b816d36de4b982b93db7a7
BLAKE2b-256 checksum
How to use checksums
4ddb4e32541c4b1f3598f95015711a202d58e1a9d1db95a4757c563a34ebbd06
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Nov 15, 2025.

Transparency log

Release files / sbomvis-0.0.0rc16-py3-none-any.whl

Download URL sbomvis-0.0.0rc16-py3-none-any.whl
Size 30.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9766508f43554062961b9caf3b07ea097ff81240b558b3e0a2f1af4b8d0caf11
BLAKE2b-256 checksum
How to use checksums
b2e31ab0f5f99d23c3037ac192b237e7b8d6a501fd9cd00fe3c8a6ada75e3141
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Nov 15, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.0rc16 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page