Skip to main content

CycloneDX bill-of-material (BOM) generation utility

Project description

The CycloneDX module for Python creates a valid CycloneDX bill-of-material document containing an aggregate of all project dependencies. CycloneDX is a lightweight BoM specification that is easily created, human readable, and simple to parse. The resulting bom.xml can be used with tools such as OWASP Dependency-Track for the continuous analysis of components.

Usage

Freezing

A bill-of-material such as CycloneDX expects exact version numbers. Therefore requirements.txt must be frozen. This can be accomplished via:

$ pip freeze > requirements.txt

Installing

$ pip install cyclonedx-bom

Options

By default, requirements.txt will be read from the current working directory and the resulting bom.xml will also be created in the current working directory. These options can be overwritten as follows:

$ cyclonedx-py
  Usage:  cyclonedx-py [OPTIONS]
  Options:
    -i <path> - the alternate filename to a frozen requirements.txt
    -o <path> - the bom file to create

License

Permission to modify and redistribute is granted under the terms of the Apache 2.0 license.

Project details


Release history Release notifications | RSS feed

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cyclonedx-bom-0.1.0.tar.gz (3.4 kB view details)

Uploaded Source

Built Distribution

cyclonedx_bom-0.1.0-py2.py3-none-any.whl (17.6 kB view details)

Uploaded Python 2 Python 3

File details

Details for the file cyclonedx-bom-0.1.0.tar.gz.

File metadata

  • Download URL: cyclonedx-bom-0.1.0.tar.gz
  • Upload date:
  • Size: 3.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.12.1 pkginfo/1.4.2 requests/2.20.1 setuptools/18.5 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/2.7.10

File hashes

Hashes for cyclonedx-bom-0.1.0.tar.gz
Algorithm Hash digest
SHA256 b5411bae2e91cdd2b5caacb153f2cfd2e460dec892591df39084ddfacac00ca9
MD5 36d7eecb13d4ba693eb266bfa0dcce1e
BLAKE2b-256 e72f56ae1cb76e8e649a2b3a1a0c3726d88c1f36e53a70d0dbe1c005e4c0c635

See more details on using hashes here.

Provenance

File details

Details for the file cyclonedx_bom-0.1.0-py2.py3-none-any.whl.

File metadata

  • Download URL: cyclonedx_bom-0.1.0-py2.py3-none-any.whl
  • Upload date:
  • Size: 17.6 kB
  • Tags: Python 2, Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.12.1 pkginfo/1.4.2 requests/2.20.1 setuptools/18.5 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/2.7.10

File hashes

Hashes for cyclonedx_bom-0.1.0-py2.py3-none-any.whl
Algorithm Hash digest
SHA256 200b8123a4b4920d5ed448b892656f94a8bcebac2be0bb5193562527363c357b
MD5 31f53eace27f79a4d76030864f5f8ab2
BLAKE2b-256 7b86c5f2d1017d362e35c4d0eb4cf3ef1f713a5f49aba453202fd8f39972c1b2

See more details on using hashes here.

Provenance

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page