SBOM Diff

Paste two resolved dependency files — old and new — and see exactly which packages were added, removed, or version-bumped. Supports npm package-lock.json, Cargo.lock, requirements.txt, and CycloneDX / SPDX SBOMs, with text, markdown, or JSON output.

Try:
Dependency diff

About this tool

SBOM Diff compares two resolved dependency files — an "old" (before) and a "new" (after) — and reports exactly which packages were added, removed, or version-bumped between them. Paste an npm package-lock.json, a Rust Cargo.lock, a Python requirements.txt, or an existing CycloneDX / SPDX software bill of materials on each side, and the tool renders the change set as a human-readable report, a markdown table for a pull request, or machine-readable JSON.

It does not run a package manager or contact a registry. A lockfile or SBOM already records the resolved dependency set, so this tool parses both sides locally in WebAssembly and compares the inventories. That makes it useful for reviewing a dependency update in code review, gating a CI job on unexpected additions, or auditing what a release actually changed. Because the comparison is a pure set diff, identical input always produces byte-identical output.

Worked example

Given this old package-lock.json:

{"name":"my-app","version":"1.0.0","lockfileVersion":3,"packages":{"":{"name":"my-app","version":"1.0.0"},"node_modules/chalk":{"version":"4.1.2"},"node_modules/left-pad":{"version":"1.3.0"}}}

and this new one (chalk bumped, left-pad dropped, lodash added):

{"name":"my-app","version":"1.1.0","lockfileVersion":3,"packages":{"":{"name":"my-app","version":"1.1.0"},"node_modules/chalk":{"version":"5.0.0"},"node_modules/lodash":{"version":"4.17.21"}}}

with output text, the result is:

Dependency diff
  added:     1
  removed:   1
  changed:   1
  unchanged: 0

Added (1)
  + npm [email protected]

Removed (1)
  - npm [email protected]

Changed (1)
  ~ npm chalk 4.1.2 -> 5.0.0  (upgraded)

Switch output to markdown for a pull-request table, or to json for a { "summary": …, "added": …, "removed": …, "changed": … } change report. Each changed package is labelled upgraded, downgraded, or changed.

Limits & notes

FAQ

What is the difference between the "old" and "new" side?

The old field is the before state and the new field is the after state. A package present only in new is reported as added, one present only in old is removed, and one whose version differs between the two is changed. Swapping the two inputs flips added and removed and inverts each upgrade/downgrade label.

Can I diff two different file formats?

Yes. Each side is detected or forced independently, so you can compare an npm package-lock.json against a CycloneDX SBOM, or last release's SPDX document against this release's Cargo.lock. The tool normalizes both to a package-URL–keyed inventory before diffing, so cross-format comparisons line up by ecosystem and package name.

How are version bumps classified?

When a package resolves to a single version on each side, the tool compares them with a numeric-aware dotted-version compare and labels the change upgraded or downgraded. If either side has multiple versions, or the versions are not orderable, the change is labelled changed without a direction.

Does it include dev dependencies?

For npm package-lock.json input, the Include npm dev / optional dependencies toggle controls whether packages marked dev or optional are counted on both sides. Cargo, pip, and SBOM inputs do not carry that distinction in this parser, so the toggle only affects npm lockfiles.

Is my data uploaded anywhere?

No. Both files are parsed and diffed in your browser through WebAssembly. The lockfile and SBOM text stay on your device unless you copy the generated diff somewhere else.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool sbom-diff '{
  "name": "my-app",
  "lockfileVersion": 3,
  "packages": {
    "": { "name": "my-app", "version": "1.0.0" },
    "node_modules/chalk": { "version": "4.1.2" }
  }
}' 'new={
  "name": "my-app",
  "lockfileVersion": 3,
  "packages": {
    "": { "name": "my-app", "version": "1.1.0" },
    "node_modules/chalk": { "version": "5.0.0" }
  }
}'

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/sbom-diff/?old=%7B%0A%20%20%22name%22%3A%20%22my-app%22%2C%0A%20%20%22lockfileVersion%22%3A%203%2C%0A%20%20%22packages%22%3A%20%7B%0A%20%20%20%20%22%22%3A%20%7B%20%22name%22%3A%20%22my-app%22%2C%20%22version%22%3A%20%221.0.0%22%20%7D%2C%0A%20%20%20%20%22node_modules%2Fchalk%22%3A%20%7B%20%22version%22%3A%20%224.1.2%22%20%7D%0A%20%20%7D%0A%7D&new=%7B%0A%20%20%22name%22%3A%20%22my-app%22%2C%0A%20%20%22lockfileVersion%22%3A%203%2C%0A%20%20%22packages%22%3A%20%7B%0A%20%20%20%20%22%22%3A%20%7B%20%22name%22%3A%20%22my-app%22%2C%20%22version%22%3A%20%221.1.0%22%20%7D%2C%0A%20%20%20%20%22node_modules%2Fchalk%22%3A%20%7B%20%22version%22%3A%20%225.0.0%22%20%7D%0A%20%20%7D%0A%7D&old_format=auto&new_format=auto&include_dev=true&output=text

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.