Reliable SBOM and Dependency Graph for C++/CMake, derived from real-world builds.

Identify duplicates, version drift, and untracked dependencies. Generate an HTML report and a CycloneDX SBOM ready for security, audit, and CI gating.

Get the CLI (free) Book a 15-min demo CMake • C++ • CycloneDX

Build-derived

No “guessing”: start from the build graph and the real targets.

Actionable

It tells you where you have duplicates and how the transitive deps propagate.

CI-ready

Artifacts and policies: Fail the pipeline when necessary, with clear rules.

In 5 minutes

# build (as you already do today)
cmake -S . -B build && cmake --build build

# generate report + sbom
depscope scan --build-dir build --out out/

# output
out/report.html
out/sbom.cdx.json

It works well on superprojects and monorepos. No backend is required to get started.

Use cases

Audit & Compliance

SBOM CycloneDX + license and component inventory for vendor assessment.

CI Governance

Block merge when an illegal or duplicate dependency appears.

Build Stability

Reduces “dependency chaos” that causes flaky builds and regressions.

Due diligence (M&A)

Quick visibility into components, licenses, and supply chain risk.

Pricing

Free

CLI + report HTML + CycloneDX. Perfect for single repos.

Pro Coming soon

GitHub/GitLab integration, gating policy, history, and dashboard.

Enterprise Coming soon

SSO, on-prem, priority support, advanced policies.

Contacts

Contact me for a demo or to become a design partner: a short call, a real case study, and a roadmap guided by your constraints.

Email me