Scan locally
Read package manifests, lock files, and native binaries. Scans run offline by default and never execute files in the selected folder.
PurpleRay / SBOM Analyzer
A small, native desktop application that turns local software artifacts into a software bill of materials. Inspect components, compare scans, and export CycloneDX.
Windows x64 · Linux x64 · Open source · Apache-2.0
From files to an inventory
Read package manifests, lock files, and native binaries. Scans run offline by default and never execute files in the selected folder.
Explore components and their evidence, compare completed scans, and review known issues through an optional OSV.dev check.
Produce a deterministic CycloneDX SBOM, export security findings, and inspect a BSI readiness report to see where inventory evidence is incomplete.
Online advisory checks are optional and require confirmation each time. They send only eligible, versioned Package URLs to OSV.dev. Readiness reporting helps review the evidence; it does not certify compliance.
Inside PurpleRay
A component inventory and a scan report keep the underlying evidence close at hand. These screenshots use synthetic illustrative data; no live advisory query was made.
Get PurpleRay
Choose the Windows or Linux package from the latest GitHub release. Installation instructions and checksums are included in the project documentation.
Download latest releaseLinux requires GTK2. WSL2 is supported with WSLg.
Package downloads across all versions
The latest release is always available on GitHub.
Recorded GitHub package downloads, including prereleases. Excludes metadata and source archives; downloads are not unique users. Deleted assets retain their last observed count. Downloads of assets deleted before tracking began cannot be recovered.