SBOM and gap scan
Annex I, Part II, point 1 requires a bill of materials in a machine-readable format. Annex I, Part I, point 2(a) requires the product to reach the market without known exploitable vulnerabilities. This checks both, and tells you which findings would actually block you.
Free, no account. Vulnerability data from OSV.dev. Lockfiles are parsed in memory and never stored.
Public GitHub and GitLab repositories. We read only dependency manifests and lockfiles — nothing else is fetched, and nothing is cloned.