Facebook Pixel

Introducing BOM Diggity

BOM Diggity’s primary purpose is to ensure the security and integrity of software programs. It incorporates secret analysis allowing the user to secure crucial information before deploying any parts of the application to the public.

Supports OCI and Docker

Generates SBOMs for container images, filesystems, and more

Scans sensitive information and secrets

Identifies Linux distribution

Converts between SBOM formats such as; CycloneDX, SPDX, etc.

Works seamlessly with Jacked

Diggity GitHub Action

A Github Action that utilizes Diggity to generate SBOM

  • Parsers Specification
  • Repository and Tar Scanning
  • Disable file listing from package metadata
  • Exclude secret searching for each specified filenames

Supported Installation OS

BOM Diggity currently supports the following operating systems:


BOM Diggity is designed to optimize the security and compliance of your software programs, and it operates smoothly on the Windows OS’ amd64 architecture.


With its support for both arm64 and amd64 architectures, Diggity enables secure generation of SBOMs for container images and filesystems on any Mac operating system.


BOM Diggity can easily detect secrets in your container images. This tool can operate on various architectures of the Linux operating system, including amd64, arm64, ppc64le, and s390x.

Supported Ecosystem

Diggity supports all of the following open-source platforms and package managers

Installation Guide

BOM Diggity is a code-driven analysis tool that maintains compliant and secure code. This page shows how to install Diggity open-source on its supported ecosystems. Get started now!



curl -sSfL https://raw.githubusercontent.com/carbonetes/diggity/main/install.sh | sh -s -- -d /usr/local/bin

You can specify a release version and destination directory for the installation:

curl -sSfL https://raw.githubusercontent.com/carbonetes/diggity/main/install.sh | sh -s -- -d <DESTINATION_DIR> -v <RELEASE_VERSION>


brew tap carbonetes/diggity
brew install diggity


scoop bucket add diggity https://github.com/carbonetes/diggity-bucket 
scoop install diggity

Useful Commands and Flags

brew tap carbonetes/diggity
brew install diggity

Available Commands and their flags with description:

diggity config [flag]
Root FlagsDescription
-d --displayDisplays the contents of the configuration file.
-h --helpHelp for configuration.
-p --pathDisplays the path of the configuration file.
-r --resetRestores default configuration file.

Output Formats

The output format for BrainIAC is configurable as well using the -o (or ‐‐output ) option:

The available formats are:

Get started with BOM Diggity

Skip to content