cyclonedx-bom
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Decision gist · record as of 2026-08-14
Yes. The tool is actively maintained, has no known vulnerabilities, low install friction, and fills a specific compliance need—generating standards-based SBOMs for Python projects. Install it if you need to produce CycloneDX documents for supply-chain security, regulatory compliance, or vulnerability tracking workflows.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >=3.9,<4; the tool is CLI-only and has no public Python API for programmatic use.
- Low install friction with six runtime dependencies; actively maintained with a release 22 days ago and 389 repository stars.
- Supports Python 3.9 through 3.14.
License · maintenance · safety
Apache-2.0 (permissive) — Apache 2.0 permissive license allows use, modification, and distribution with minimal restrictions—suitable for both open-source and proprietary projects.
last release 2026-07-23 (22 days) · last repo commit 2026-08-12 · 389 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 2,417,736 downloads/mo, #3,073 on PyPI
Alternatives
Verify before relying
pip install cyclonedx-bom
cyclonedx-py environment --output-file sbom.json
# or: cyclonedx-py requirements --input requirements.txt --output-file sbom.json- Whether the tool can validate SBOMs against CycloneDX schema versions beyond what the description implies
- Support status for Python 2.7 in older versions and which versions those are
What it is and what it does
cyclonedx-bom is a command-line tool that reads Python project metadata and generates standardized SBOM documents in CycloneDX format. It works by scanning Python virtual environments, Poetry and Pipenv manifests, pip requirements files, and PDM/uv environments to extract dependency information, then serializes that data according to official CycloneDX specifications and optional namespace taxonomies for Python-specific properties.
The tool is designed for compliance and security workflows where you need a complete, accurate inventory of software components and their versions. It depends on cyclonedx-python-lib for the actual SBOM data structures, packageurl-python for component URLs, pip-requirements-parser for parsing requirements files, and chardet and tomli for encoding and configuration handling. The resulting SBOMs can approach OWASP SCVS Level-2 compliance (external signing required).
Use it for
- Generate SBOMs for supply-chain security audits and compliance reporting
- Create dependency inventories from Poetry or Pipenv projects for vulnerability scanning
- Export Python virtual environment contents as standardized SBOM for CI/CD pipelines
- Build component catalogs from requirements.txt for license and security analysis
- Integrate SBOM generation into build tools to track software composition over time
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The tool is actively maintained, has no known vulnerabilities, low install friction, and fills a specific compliance need—generating standards-based SBOMs for Python projects. Install it if you need to produce CycloneDX documents for supply-chain security, regulatory compliance, or vulnerability tracking workflows.
Install
cyclonedx-bom on PyPI
Before you install
Low install friction with six runtime dependencies; actively maintained with a release 22 days ago and 389 repository stars. Supports Python 3.9 through 3.14.
Requires Python >=3.9,<4; the tool is CLI-only and has no public Python API for programmatic use.
License in practice
Apache 2.0 permissive license allows use, modification, and distribution with minimal restrictions—suitable for both open-source and proprietary projects.
Quickstart
pip install cyclonedx-bom
cyclonedx-py environment --output-file sbom.json
# or: cyclonedx-py requirements --input requirements.txt --output-file sbom.json
Verify before relying
- Whether the tool can validate SBOMs against CycloneDX schema versions beyond what the description implies
- Support status for Python 2.7 in older versions and which versions those are
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release <4.0,>=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 6 packageschardetcyclonedx-python-libpackageurl-pythonpackagingpip-requirements-parsertomli |
| Maintenance | Actively maintained 22 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 2,417,736 / month, #3,073 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyIntended Audience :: Legal IndustryIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software DevelopmentTopic :: System :: Software DistributionTyping :: Typed |
Evidence: cyclonedx_bom-7.3.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “dependency inventory tool”
- cyclonedx-bomGenerates Software Bill of Materials (SBOM) documents in CycloneDX…
- pip-licenses-cliA command-line tool that scans installed Python packages and reports…
- pip-licenses-libProgrammatically retrieve and inspect the software licenses of Python…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also cyclonedx-py · cyclonedx-python-lib · distro2sbom · lib4sbom · lib4vex · pdm · scancode-toolkit · spdx-python-model · socketdev · pipenv