The open-source platform for software supply chain security.
Trustify brings SBOMs, vulnerability advisories, and VEX documents into a single searchable system — so you can understand what's in your software and respond to threats in minutes, not days.
| Unified SBOM Management | Ingest, store, and search CycloneDX and SPDX SBOMs in one place |
| Vulnerability Intelligence | Cross-reference SBOMs against advisories from Red Hat, GHSA, NVD, and OSV |
| VEX Support | Reduce alert fatigue with vendor vulnerability exploitability data (CSAF/VEX) |
| Built-in Importers | Automatically fetch and stay current with public vulnerability feeds |
| REST API & Web UI | Full API with OpenAPI spec, plus a modern web interface |
| Single Binary Deployment | One binary, one PostgreSQL database — no microservices to wrangle |
Download the latest trustd-pm binary from
Releases, then:
AUTH_DISABLED=true ./trustd-pmAUTH_DISABLED=true cargo run --bin trustdThis starts Trustify in "PM mode" — an embedded PostgreSQL database is created in .trustify/ in your current directory. No external setup needed.
- Web UI: http://localhost:8080
- REST API: http://localhost:8080/openapi/
cd etc/datasets && make
curl -X POST http://localhost:8080/api/v3/dataset --data-binary @ds1.zip \
-H "Content-Type: application/zip"Note: PM mode requires IPv6 enabled with localhost resolving to
::1.
A rolling nightly build is published from the latest main commit each day by the
nightly workflow. Runs are skipped when main has not
changed since the previous nightly or when CI has not passed. A manual run can rebuild
unchanged main, but still requires CI to pass.
- Binaries: Nightly release
- Container images:
ghcr.io/guacsec/trustd:nightly,ghcr.io/guacsec/xtask:nightly, andghcr.io/guacsec/gensbom:nightly. Each build also has a date-and-commit-specific tag.
Not for production use. Nightly builds are experimental and unsupported. They may be unstable or include breaking changes, including database migrations that can make existing data incompatible. Use a stable, versioned release for production deployments.
| Term | What it means in Trustify |
|---|---|
| SBOM | A software bill of materials (CycloneDX or SPDX) describing the components in a software product |
| Advisory | A security advisory (e.g. from NVD, Red Hat, GHSA) describing vulnerabilities in specific packages |
| VEX | Vendor exploitability exchange — a statement from a vendor about whether a vulnerability actually affects their product |
| pURL | Package URL — a standard way to identify a software package across ecosystems |
| CPE | Common Platform Enumeration — an identifier for products, used in NVD advisories |
| CVE | A unique identifier for a publicly known security vulnerability |
We welcome contributions! To get started:
- Install Rust
- Start PostgreSQL:
podman-compose -f etc/deploy/compose/compose.yaml up - Run the tests:
cargo test
See CONVENTIONS.md for coding standards and docs/ for architecture decisions, OIDC setup, and deployment guides.
| Repository | Description |
|---|---|
| trustify-ui | Web interface |
| trustify-helm-charts | Helm charts for Kubernetes deployment |
| trustify-mcp | MCP server for AI/LLM integration |
| trustify-load-test-runs | Scale test runner and results |
| scale-testing | Scale test suite |
| trustify-release-tools | Release automation |
Trustify uses a modulith architecture — a single deployable binary backed by PostgreSQL.
- REST API for ingesting and querying supply-chain data
- Built-in importers that fetch public vulnerability feeds on a schedule
- Extensible data model supporting SBOMs, advisories, VEX, pURLs, and CPEs
- OIDC authentication with optional dev/test bypass
Apache-2.0 — see LICENSE for details.


