Type any Hugging Face model ID, supply the few facts the Hub cannot know, and generate a resolved CycloneDX 1.6 AIBOM against the live registry — then check it against the advisories that actually affect the loading stack.
Step 1
Only the model ID is required. Everything else either comes from the Hub, or is something the Hub structurally cannot know — jurisdiction and legal entity have no field in CycloneDX or SPDX, and no registry publishes them.
The org/name path from the model's Hub URL.
Leave blank to resolve the current head and pin whatever SHA it returns.
The Hub gives an org handle, not a legal person. Nobody to serve an advisory on otherwise.
Decides whether hosted use is an export. No native field exists — it goes in as a property.
The BOM subject.
Used to check the advisories below. Nothing is sent anywhere.
If the live fetch is blocked, run the command below in a terminal and paste the output.
Reference
Every advisory in this tool sits in the SBOM and AIBOM overlap. That is the whole argument for merging them rather than filing an AIBOM and calling the job done.