Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings
CycloneDX

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings
@CycloneDX

CycloneDX BOM Standard

CycloneDX is a modern standard for the software supply chain. SBOM, SaaSBOM, CBOM, OBOM, VEX, and more. CycloneDX is a OWASP project ratified as ECMA-424

CycloneDX logo

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. The specification supports:

  • Software Bill of Materials (SBOM)
  • Software-as-a-Service Bill of Materials (SaaSBOM)
  • Hardware Bill of Materials (HBOM)
  • Machine Learning Bill of Materials (ML-BOM)
  • Cryptography Bill of Materials (CBOM)
  • Manufacturing Bill of Materials (MBOM)
  • Operations Bill of Materials (OBOM)
  • Vulnerability Disclosure Reports (VDR)
  • Vulnerability Exploitability eXchange (VEX)
  • CycloneDX Attestations (CDXA)

The CycloneDX project provides standards in XML, JSON, and Protocol Buffers, as well as a largecollection of official and community supported toolsthat create or interoperate with the standard.

The project's website has many documenteduse cases and examplesthat provide a springboard to SBOM adoption.

The project operates as ameritocracywhoseguiding principlesreinforce itsrisk-based approach to standards development.The project encouragescommunity participationin the development of thestandard and supporting tools.

Background

Modern software is assembled using third-party and open source components. They are glued together in complex andunique ways and integrated with original code to achieve the desired functionality. An accurate inventory of allcomponents enables organizations to identify risk, allows for greater transparency, and enables rapid impact analysis.

CycloneDX was created for this purpose.

Strategic direction and maintenance of the specification is managed by the CycloneDX Core Working Group,is backed by theOWASP Foundation,and is supported by the global information security community.

PinnedLoading

  1. specificationspecificationPublic

    OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, an…

    XSLT 403 68

  2. cyclonedx-pythoncyclonedx-pythonPublic

    CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments

    Python 299 76

  3. cyclonedx-maven-plugincyclonedx-maven-pluginPublic

    Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects

    Java 324 92

  4. cyclonedx-clicyclonedx-cliPublic

    CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.

    C# 381 67

  5. bom-examplesbom-examplesPublic

    A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)

    196 72

  6. cyclonedx-node-modulecyclonedx-node-modulePublic

    creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects

    129 38

Repositories

Loading
Type
Select type
Language
Select language
Sort
Select order
Showing 10 of 63 repositories
  • cyclonedx-python Public

    CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments

    CycloneDX/cyclonedx-python’s past year of commit activity
    Python 299Apache-2.0 76 20(13 issues need help) 6 UpdatedJul 9, 2025
  • cdxgen Public

    Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server

    CycloneDX/cdxgen’s past year of commit activity
    JavaScript 732Apache-2.0 198 378(27 issues need help) 16 UpdatedJul 9, 2025
  • cyclonedx-cli Public

    CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.

    CycloneDX/cyclonedx-cli’s past year of commit activity
    C# 381Apache-2.0 67 102(1 issue needs help) 14 UpdatedJul 9, 2025
  • cyclonedx-python-lib Public

    Python implementation of OWASP CycloneDX

    CycloneDX/cyclonedx-python-lib’s past year of commit activity
    Python 83Apache-2.0 52 21(14 issues need help) 9 UpdatedJul 8, 2025
  • cyclonedx-core-java Public

    CycloneDX SBOM Model and Utils for Creating and Validating BOMs

    CycloneDX/cyclonedx-core-java’s past year of commit activity
    Java 94Apache-2.0 72 30(2 issues need help) 8 UpdatedJul 8, 2025
  • cyclonedx-gradle-plugin Public

    Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects

    CycloneDX/cyclonedx-gradle-plugin’s past year of commit activity
    Java 192Apache-2.0 81 65(3 issues need help) 5 UpdatedJul 8, 2025
  • cyclonedx-node-yarn Public

    Create CycloneDX Software Bill of Materials (SBOM) from Node.js Yarn projects.

    CycloneDX/cyclonedx-node-yarn’s past year of commit activity
    JavaScript 23Apache-2.0 6 14(12 issues need help) 6 UpdatedJul 8, 2025
  • cyclonedx-php-library Public

    PHP Implementation of OWASP CycloneDX Bill of Materials (BOM)

    CycloneDX/cyclonedx-php-library’s past year of commit activity
    PHP 9Apache-2.00 12(4 issues need help) 3 UpdatedJul 6, 2025
  • cyclonedx-cocoapods Public

    Creates CycloneDX Software Bill-of-Materials (SBOM) from Objective-C and Swift projects that use CocoaPods.

    CycloneDX/cyclonedx-cocoapods’s past year of commit activity
    Ruby 23Apache-2.0 16 1 0 UpdatedJul 6, 2025
  • cyclonedx-php-composer Public

    Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects

    CycloneDX/cyclonedx-php-composer’s past year of commit activity
    PHP 66Apache-2.0 7 15(9 issues need help) 2 UpdatedJul 5, 2025

[8]ページ先頭

©2009-2025 Movatter.jp