ActaSeal Source & CLI

CBOM Check

Semantic checks for CycloneDX 1.6 and 1.7 Cryptography Bills of Materials.

Passing the schema does not mean a CBOM is correct. This checks what the CBOM says: NIST levels against FIPS 203/204/205, asset modelling, incomplete parameter-set names, missing classical algorithms, refresh against a previous version, and agreement with an ACVP test report.

Loading Python engine (about 15 MB, cached after the first visit)…

Try a sample: · ·

Reviewing CBOMs from many vendors, or need proof that a CBOM passed and when? ActaSeal seals the result so your auditor can verify it offline. Talk to us →

Checks

Limits

The assetType check is a heuristic; every other check is deterministic. It does not check inventory completeness, key lengths, certificate contents, or whether an ACVP report is genuine. Self-run test vectors are not CAVP validation.

Privacy

The checker is Python running in your browser (Pyodide). Your files are read locally and never sent anywhere. The same code runs as a CLI: python cbom_check.py cbom.json --acvp report.json --baseline old.json --strict