Directory context | AI Supply-Chain Security
BomLens
Local-first SBOM generator that builds CycloneDX ML-BOMs for Hugging Face models, with license and known-vulnerability reports
Direct answer
What is BomLens?
BomLens is included in the Awesome MLSecOps AI Supply-Chain Security directory. The community-maintained README describes it as: “Local-first SBOM generator that builds CycloneDX ML-BOMs for Hugging Face models, with license and known-vulnerability reports.” Its MLSecOps relevance is the protection of model provenance, artifact integrity, dependencies, signing, bills of materials, registries, or delivery pipelines. The linked first-party source is the sktelecom/bomlens repository on GitHub. A technical review should test the project's documented evidence across four criteria: Provenance and signing support, ML-BOM formats, Registry and CI integration, and Policy enforcement. Compare that evidence with the intended architecture and threat model. Catalog inclusion establishes relevance to this security category; it is not a certification, comparative ranking, or endorsement. Confirm current capabilities, maintenance, licensing, limitations, and deployment assumptions in the first-party documentation before adoption.
Local-first SBOM generator that builds CycloneDX ML-BOMs for Hugging Face models, with license and known-vulnerability reports
Neutral catalog description synchronized from the Awesome MLSecOps README
Before adoption
What should teams verify about BomLens?
Answer these questions from current first-party documentation and testing evidence rather than relying on the directory listing alone.
- 01
Which artifacts, identities, hashes, signatures, and provenance records are covered?
- 02
Which CycloneDX, SPDX, SLSA, Sigstore, or model-specific formats are supported?
- 03
Can evidence be verified across build, registry, conversion, and deployment boundaries?
- 04
How are trust roots, policy exceptions, key management, and failures handled?