---
title: Enhancing security with OWASP dep-scan and CycloneDX 1.6 on sbom.sh
description: Enhance software security with OWASP dep-scan and CycloneDX 1.6 on sbom.sh for robust, up-to-date vulnerability scanning and SBOM generation.
image: https://codenotary.com/hubfs/image-png-Apr-18-2024-10-05-02-9445-AM.png
---

**$ protect --distro linux --machines 25 --free**

[Start now](https://apps.codenotary.com/linux)

[![cn-logo-black-nobg](https://codenotary.com/hubfs/cn-logo-black-nobg.svg)](https://codenotary.com/)

- Product
  
  #### [![AgentMon Start](https://codenotary.com/hubfs/AgentMon%20Start.svg) **AgentMon Start** Organization-wide AI agent spend, security and device fleet TRY NOW →](https://apps.codenotary.com/agentmon-start)
  
  #### [![AgentMon for Enterprise](https://codenotary.com/hubfs/AgentMon%20for%20Enterprise.svg) **AgentMon** Currently monitors more \> 7 million agent interactions/day. TRY NOW →](https://codenotary.com/agentmon)
  
  #### [![AgentX](https://codenotary.com/hubfs/AgentX.svg) **AgentX** Agentic network control middleware. TRY NOW →](https://codenotary.com/agent-network-control)
  
  #### [![Autonomous Security](https://codenotary.com/hubfs/Autonomous%20Security.svg) **Autonomous Security** AI Agents keep your servers secure. TRY NOW →](https://codenotary.com/trust)
- Use Cases
  
  #### [**AI Agent Risk Monitoring** Continuous oversight of autonomous agents across every environment.](https://codenotary.com/use-cases#risk)
  
  #### [**Autonomous Security Operations** Self-healing defenses that detect, contain, and remediate threats.](https://codenotary.com/use-cases#agentops)
  
  #### [**AI Coding Governance & Performance Monitoring** AI-generated code reviewed, tracked, and held to quality standards.](https://codenotary.com/use-cases#performance)
  
  #### [**AI Tool Cost & Usage Optimization** Spend and consumption optimized across every AI service in use.](https://codenotary.com/use-cases#cost)
  
  #### [**AI Tool Security & Policy Enforcement** Approved AI usage enforced with guardrails and policy controls.](https://codenotary.com/use-cases#security#security)
  
  #### [**Shadow AI Governance** Unsanctioned AI tools discovered, surfaced, and brought under control.](https://codenotary.com/use-cases#shadowit)
- [Blog](https://codenotary.com/blog)
- [Press](https://codenotary.com/press)
- Resources
  
  #### [**Integrations** Connect with your favorite tools and platforms. LEARN MORE →](https://codenotary.com/integrations)
  
  #### [**Support** Get help from our dedicated support team. GET HELP →](https://support.codenotary.com)
  
  #### [**Success Stories** Read how customers achieve their goals. READ MORE →](https://codenotary.com/success)
  
  #### [**Learn** Access documentation and learning resources. EXPLORE →](https://codenotary.com/learn)

[Login](https://apps.codenotary.com/auth/login)

[All posts](https://codenotary.com/blog/all)

 Apr 18, 2024

# Enhancing security with OWASP dep-scan and CycloneDX 1.6 on sbom.sh

 By  [Dennis](https://codenotary.com/blog/author/dennis)  ·   2 minute read

In a significant upgrade for developers and DevOps engineers, [https://sbom.sh](https://sbom.sh) has integrated OWASP dep-scan, a robust vulnerability scanner, along with support for CycloneDX 1.6, the latest standard in software bill of materials (SBOM) formats.

The lack of support for latest SBOM standards can potentially lead to missed vulnerabilities and lull yourself into a false sense of security.

This upgrade marks a crucial enhancement in the tools available for software composition analysis, vulnerability scanning and security auditing.

![](https://codenotary.com/hs-fs/hubfs/image-png-Apr-18-2024-10-05-02-9445-AM.png?width=1232&height=886&name=image-png-Apr-18-2024-10-05-02-9445-AM.png)

### Introduction to OWASP dep-scan

The OWASP dep-scan is an open-source project designed to provide comprehensive vulnerability scanning for project dependencies. By leveraging this tool, developers can identify and mitigate security risks associated with third-party packages and libraries used in their software projects. The tool's integration into sbom.sh enhances the platform's capability to deliver latest, actionable insights into potential vulnerabilities. You can explore more about OWASP dep-scan on its [GitHub page](https://github.com/owasp-dep-scan/dep-scan).

### CycloneDX 1.6 Support

CycloneDX is a SBOM standard designed for use in application security contexts and supply chain component analysis. The release of [CycloneDX 1.6](https://cyclonedx.org/news/cyclonedx-v1.6-released/) brings several improvements, including enhanced support for vulnerability disclosure and resolution. This standard has become a crucial tool for managing software supply chain security efficiently.

sbom.sh's adoption of CycloneDX 1.6 and OWASP dep-scan allows users to generate SBOMs that comply with the latest industry standards, facilitating better integration with other tools and systems. This support is particularly significant as it addresses some of the limitations of other popular tools such as Grype and Trivy, which currently do not support CycloneDX 1.6. More detailed information about this support can be found in this [announcement](https://codenotary.com/blog/codenotary-to-support-updated-sbom-standards-cyclonedx-1.6-and-spdx-3.0).

![](https://codenotary.com/hs-fs/hubfs/image-png-Apr-18-2024-10-07-40-7786-AM.png?width=963&height=131&name=image-png-Apr-18-2024-10-07-40-7786-AM.png)

![](https://codenotary.com/hs-fs/hubfs/image-png-Apr-18-2024-10-09-34-0236-AM.png?width=1589&height=542&name=image-png-Apr-18-2024-10-09-34-0236-AM.png)

### The Edge of Using OWASP dep-scan

One of the most compelling advantages of incorporating OWASP dep-scan into sbom.sh is its ability to offer precise and reliable scanning results. Unlike some other scanners that might not yet support the latest SBOM standards, dep-scan provides compatibility with CycloneDX 1.6, ensuring that the vulnerability scanning process is both thorough and up-to-date with current security practices.

![](https://codenotary.com/hs-fs/hubfs/image-png-Apr-18-2024-10-10-26-9980-AM.png?width=1588&height=824&name=image-png-Apr-18-2024-10-10-26-9980-AM.png)

### Practical Implications for DevOps

For DevOps teams, the integration of OWASP dep-scan and CycloneDX 1.6 into [https://sbom.sh](https://sbom.sh) means more than just enhanced security. It signifies an easier, more efficient workflow for identifying vulnerabilities and generating SBOMs that adhere to the latest standards. This can significantly reduce the time and effort required for audits and compliance checks, making security practices more streamlined and less obstructive to rapid development cycles.

### Appreciation for Contributions

It is important to acknowledge the contributions of those who have made these integrations possible. A special thanks to [Prabhu](https://github.com/prabhu) for his invaluable support in integrating these powerful tools into sbom.sh. His efforts have greatly contributed to making the platform more robust and capable of meeting the evolving needs of modern software development environments.

### Conclusion

The addition of OWASP dep-scan and support for CycloneDX 1.6 to sbom.sh is a great step forward in the pursuit of enhanced software security. By adopting these tools, developers and DevOps teams can ensure their products are built on secure, reliable foundations.

As the landscape of software security continues to evolve, tools like sbom.sh are essential for staying ahead of potential risks and safeguarding software against emerging threats.

[![Share on twitter](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/twitter-color.png?width=35&height=35&name=twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://codenotary.com/blog/enhanced-security-with-owasp-dep-scan-and-cyclonedx-1.6-on-sbom.sh&utm_medium=social&utm_source=twitter&url=https://codenotary.com/blog/enhanced-security-with-owasp-dep-scan-and-cyclonedx-1.6-on-sbom.sh&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on facebook](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/facebook-color.png?width=35&height=35&name=facebook-color.png)](http://www.facebook.com/share.php?u=https://codenotary.com/blog/enhanced-security-with-owasp-dep-scan-and-cyclonedx-1.6-on-sbom.sh&utm_medium=social&utm_source=facebook) [![Share on linkedin](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/linkedin-color.png?width=35&height=35&name=linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://codenotary.com/blog/enhanced-security-with-owasp-dep-scan-and-cyclonedx-1.6-on-sbom.sh&utm_medium=social&utm_source=linkedin) [![Share on pinterest](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/pinterest.jpg?width=35&height=35&name=pinterest.jpg)](http://pinterest.com/pin/create/button/?url=https://codenotary.com/blog/enhanced-security-with-owasp-dep-scan-and-cyclonedx-1.6-on-sbom.sh&utm_medium=social&utm_source=pinterest&media=)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Dennis",
    "url" : "https://codenotary.com/blog/author/dennis"
  },
  "dateModified" : "2024-05-01T08:11:50.405Z",
  "datePublished" : "2024-04-18T13:18:04.000Z",
  "headline" : "Enhancing security with OWASP dep-scan and CycloneDX 1.6 on sbom.sh",
  "image" : [ "https://codenotary.com/hubfs/image-png-Apr-18-2024-10-05-02-9445-AM.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://codenotary.com/blog/enhanced-security-with-owasp-dep-scan-and-cyclonedx-1.6-on-sbom.sh",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://codenotary.com/hubfs/logo-light.svg"
    },
    "name" : "Codenotary, Inc."
  }
}
```

```json
{
  "@context" : "http://schema.org",
  "@type" : "Article",
  "author" : {
    "@type" : "Person",
    "name" : [ "Dennis" ],
    "url" : "https://codenotary.com/blog/author/dennis"
  },
  "datePublished" : "2024-04-18T13:18:04+0000",
  "description" : "Enhance software security with OWASP dep-scan and CycloneDX 1.6 on sbom.sh for robust, up-to-date vulnerability scanning and SBOM generation.",
  "headline" : "Enhancing security with OWASP dep-scan and CycloneDX 1.6 on sbom.sh",
  "image" : "https://23873599.fs1.hubspotusercontent-na1.net/hubfs/23873599/image-png-Apr-18-2024-10-05-02-9445-AM.png",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://cdn2.hubspot.net/hubfs/23873599/logo-light.svg"
    },
    "name" : ""
  },
  "url" : "https://codenotary.com/blog/enhanced-security-with-owasp-dep-scan-and-cyclonedx-1.6-on-sbom.sh"
}
```