Software, crypto & AI inventory
Turn individual scans into a component inventory your team can use.
When a component becomes a concern, the next question is which repositories contain it and who owns them. Code Security connects uploaded software inventories to the organisation's repository view. Separate cryptographic and AI inventories help teams investigate algorithms, libraries, SDKs and recognised model patterns without treating them as interchangeable asset lists.
- Software
- Packages · versions · available relationshipsWhich components need review?
- Cryptography
- Algorithms · libraries · recognised usageWhere should a crypto migration begin?
- AI
- SDKs · model patterns · dependency evidenceWhich teams need to confirm AI usage?
Conceptual inventory map. Each inventory has its own command, output and coverage.
| Inventory | Question it helps answer | Coverage boundary |
|---|---|---|
| SBOM / software | Which recognised components and versions are in these repositories? | Source and resolved dependency evidence, not a complete runtime asset discovery |
| CBOM / cryptography | Where do supported crypto algorithms, libraries and relationships appear? | Recognised usage; uncertain and indirect usage can remain unassessed |
| AIBOM / AI | Where do supported AI SDK and model patterns appear? | Pattern evidence, not observed provider traffic or a model behaviour audit |
01 / Software, crypto & AI inventory
Answer a cross-repository component question
The software inventory brings recognised package names, versions, ecosystems and repository associations into one place. A security owner can inspect the entries connected to a relevant advisory and identify the repositories that need follow-up, instead of asking every team to find its latest report.
Inventory freshness matters as much as a component count. A repository that has not uploaded a recent scan may be out of date, and a repository that never uploaded cannot be included. Use the latest scan context and ownership records when planning a campaign.
02 / Software, crypto & AI inventory
Give cryptography and AI their own review context
A cryptographic bill of materials records recognised algorithms, libraries, certificates and usage relationships within supported analysis. It gives engineers a starting point for investigating weak primitives, certificate use or a cryptographic migration. Discovery alone does not establish complete key coverage or post-quantum readiness.
The AI inventory recognises supported AI SDK and model patterns in source and dependency files. That can help locate the teams that should answer questions about provider use or model handling. A pattern match does not observe network traffic or prove that source code was sent to a particular model.
03 / Software, crypto & AI inventory
Export the artifact that matches the question
Use software BOM formats for component inventories, cryptographic representations for supported crypto evidence and ML-BOM output for recognised AI components. SARIF describes findings and serves a different purpose. Choose the export according to the recipient's workflow and check which information the format can represent.
The organisation-wide software and AI inventory views belong to Business and Enterprise. Local scanning and inventory-generation capabilities are available across plans, subject to the selected command and supported inputs. Buying a higher plan does not turn an unrecognised component into a recognised one.
Put it to work
Start with one representative repository.
Bring one service into the inventory
Scan with the relevant inventory option and use the correct repository identity when uploading. Keep different products and branches distinguishable.
Investigate a component
Review package identity, advisory details, associated repositories and scan freshness. Ask the responsible team to confirm the affected build.
Follow the change
Rescan after upgrades or replacements and review the new inventory. Export the relevant artifact for procurement, engineering or a customer assessment.
magdox scan --sbom --repository checkout-api --upload .
magdox aibom --repository checkout-api --upload .
magdox cbom .AIBOM is a separate command. The CBOM command produces a local cryptographic inventory. Uploaded inventory views cover participating repositories and the scan versions received by the server.
Before you start
Scope and practical questions.
Does the inventory cover repositories we do not upload?
No. Local-only results stay outside the shared inventory. Scope and freshness are determined by the uploaded evidence.
Does a model name prove that our data reached that provider?
No. AI inventory identifies recognised code and dependency patterns. Confirm actual data handling with the application owner and your operational controls.
Explore Code Security
Source-code analysis
Local SAST with affected locations, supported flow evidence, severity, confidence and explicit analysis coverage.
Dependency security
Review known vulnerabilities, malicious-package indicators and unresolved dependency versions from the repository's own manifests and lockfiles.
Secrets & configuration
Review source, infrastructure definitions and delivery configuration locally, with redacted secret findings and file-level context.
Code Security · next step
Evaluate the workflow on your own code.
Use a repository your team understands, review the findings with its engineers and decide how the result fits your delivery process.
14-day self-service trial. Card required; cancel before the trial ends to avoid the first charge.