Skip to main content

CycloneDX bill-of-material (BOM) generation utility

Project description

The CycloneDX module for Python creates a valid CycloneDX bill-of-material document containing an aggregate of all project dependencies. CycloneDX is a lightweight BoM specification that is easily created, human readable, and simple to parse. The resulting bom.xml can be used with tools such as OWASP Dependency-Track for the continuous analysis of components.

Usage

Freezing

A bill-of-material such as CycloneDX expects exact version numbers. Therefore requirements.txt must be frozen. This can be accomplished via:

$ pip freeze > requirements.txt

Installing

$ pip install cyclonedx-bom

Options

By default, requirements.txt will be read from the current working directory and the resulting bom.xml will also be created in the current working directory. These options can be overwritten as follows:

$ cyclonedx-py
  Usage:  cyclonedx-py [OPTIONS]
  Options:
    -i <path> - the alternate filename to a frozen requirements.txt
    -o <path> - the bom file to create

License

Permission to modify and redistribute is granted under the terms of the Apache 2.0 license.

Project details


Release history Release notifications | RSS feed

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cyclonedx-bom-0.2.0.tar.gz (4.4 kB view details)

Uploaded Source

Built Distribution

cyclonedx_bom-0.2.0-py2.py3-none-any.whl (19.5 kB view details)

Uploaded Python 2 Python 3

File details

Details for the file cyclonedx-bom-0.2.0.tar.gz.

File metadata

  • Download URL: cyclonedx-bom-0.2.0.tar.gz
  • Upload date:
  • Size: 4.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.12.1 pkginfo/1.4.2 requests/2.20.1 setuptools/18.5 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/2.7.10

File hashes

Hashes for cyclonedx-bom-0.2.0.tar.gz
Algorithm Hash digest
SHA256 5c3135dddabe3d3110d11da148e101022898c73e6c3f8cfc939821fb4eb56828
MD5 6fb0f71191b236f5aada65cec1a9abb8
BLAKE2b-256 a279501b3b303b90c9b3385a12f65888b175d5fa7924b7bfa57b8283fd1a6598

See more details on using hashes here.

Provenance

File details

Details for the file cyclonedx_bom-0.2.0-py2.py3-none-any.whl.

File metadata

  • Download URL: cyclonedx_bom-0.2.0-py2.py3-none-any.whl
  • Upload date:
  • Size: 19.5 kB
  • Tags: Python 2, Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.12.1 pkginfo/1.4.2 requests/2.20.1 setuptools/18.5 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/2.7.10

File hashes

Hashes for cyclonedx_bom-0.2.0-py2.py3-none-any.whl
Algorithm Hash digest
SHA256 448cac42ef0198cb5187129683c8860870e6fda820fc55c937115bcf58e48762
MD5 4fe3f29ce4556d1cec9e993ae0df49d0
BLAKE2b-256 f95fa217122637b4b43b7fe602ff6f147b7c1417670b381d69d6e0617cbb2c23

See more details on using hashes here.

Provenance

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page