Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

CycloneDX

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
@CycloneDX

CycloneDX BOM Standard

CycloneDX is a modern standard for the software supply chain. SBOM, SaaSBOM, CBOM, OBOM, VEX, and more. CycloneDX is a OWASP project ratified as ECMA-424

CycloneDX logo

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. The specification supports:

  • Software Bill of Materials (SBOM)
  • Software-as-a-Service Bill of Materials (SaaSBOM)
  • Hardware Bill of Materials (HBOM)
  • Machine Learning Bill of Materials (ML-BOM)
  • Cryptography Bill of Materials (CBOM)
  • Manufacturing Bill of Materials (MBOM)
  • Operations Bill of Materials (OBOM)
  • Vulnerability Disclosure Reports (VDR)
  • Vulnerability Exploitability eXchange (VEX)
  • CycloneDX Attestations (CDXA)

The CycloneDX project provides standards in XML, JSON, and Protocol Buffers, as well as a largecollection of official and community supported toolsthat create or interoperate with the standard.

The project's website has many documenteduse cases and examplesthat provide a springboard to SBOM adoption.

The project operates as ameritocracywhoseguiding principlesreinforce itsrisk-based approach to standards development.The project encouragescommunity participationin the development of thestandard and supporting tools.

Background

Modern software is assembled using third-party and open source components. They are glued together in complex andunique ways and integrated with original code to achieve the desired functionality. An accurate inventory of allcomponents enables organizations to identify risk, allows for greater transparency, and enables rapid impact analysis.

CycloneDX was created for this purpose.

Strategic direction and maintenance of the specification is managed by the CycloneDX Core Working Group,is backed by theOWASP Foundation,and is supported by the global information security community.

PinnedLoading

  1. specificationspecificationPublic

    OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, an…

    XSLT 389 66

  2. cyclonedx-pythoncyclonedx-pythonPublic

    CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments

    Python 276 71

  3. cyclonedx-maven-plugincyclonedx-maven-pluginPublic

    Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects

    Java 316 88

  4. cyclonedx-clicyclonedx-cliPublic

    CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.

    C# 345 63

  5. bom-examplesbom-examplesPublic

    A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)

    191 69

  6. cyclonedx-node-modulecyclonedx-node-modulePublic

    creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects

    126 38

Repositories

Loading
Type
Select type
Language
Select language
Sort
Select order
Showing 10 of 60 repositories

[8]ページ先頭

©2009-2025 Movatter.jp