$npx skillfedfor your agent

cyclonedx-python-lib

Python library for CycloneDX

Worth itPyPI Software DevelopmentReleased Aug 202635.7M downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — cyclonedx_python_lib-11.12.0-py3-none-any.whl
v11.12.0 · released 2026-08-13 · Python <4.0,>=3.9 · 5 runtime deps: license-expression, packageurl-python, py-serializable, sortedcontainers, typing_extensions

Yes. This is a production-stable, actively maintained library with no known vulnerabilities, low install friction, and permissive licensing. Install it if you are building tooling that needs to create, read, or validate CycloneDX documents; do not install it as a standalone SBOM generator—use CycloneDX Python or Jake for that instead.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later; does not support Python 2 or versions below 3.9.
  • Low friction install with five straightforward runtime dependencies.
  • Actively maintained as of 2026-08-13 with no known vulnerabilities and production-stable status.

License · maintenance · safety

Apache-2.0 (permissive) — Apache 2.0 permissive license allows free use, modification, and redistribution with minimal restrictions—suitable for both open-source and proprietary projects.

last release 2026-08-13 (1 days) · last repo commit 2026-08-13 · 113 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 35,721,532 downloads/mo, #742 on PyPI

Verify before relying

pip install cyclonedx-python-lib

from cyclonedx.model import Component, ComponentType
from cyclonedx.output import make_outputter

component = Component(name="example", version="1.0", component_type=ComponentType.LIBRARY)
outputter = make_outputter(component, output_format="json")
print(outputter.output_as_string())
  • Whether the library supports all CycloneDX specification versions or only recent ones
  • Performance characteristics when handling very large BOMs with thousands of components
  • Specific validation rules enforced by the validators beyond standard CycloneDX compliance
Same gist for agents: .md · .json

What it is and what it does

CycloneDX Python Library is a data-modeling and validation toolkit for working with CycloneDX Bill of Materials documents. It provides Python classes and methods to construct, validate, and serialize BOM structures that describe software components, services, hardware, and AI elements—enabling teams to document supply-chain composition and track dependencies for security and compliance purposes.

The library is designed as a foundation for other tools rather than a standalone application. It handles the low-level mechanics of BOM creation and rendering: defining component types, managing dependencies, encoding metadata like PackageURLs and license expressions, and outputting to standard formats. Teams building SBOM generators, vulnerability disclosure tools (VEX/VDR), or supply-chain analysis platforms typically use this library as their core data layer.

Use it for

  • Building custom SBOM generation tools that need to programmatically create and validate CycloneDX documents
  • Integrating BOM generation into CI/CD pipelines to automatically track software composition
  • Parsing and transforming existing CycloneDX BOMs for compliance reporting or supply-chain audits
  • Embedding BOM support into package managers or dependency analysis tools
  • Creating VEX or VDR documents to communicate vulnerability and remediation information

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

This is a production-stable, actively maintained library with no known vulnerabilities, low install friction, and permissive licensing. Install it if you are building tooling that needs to create, read, or validate CycloneDX documents; do not install it as a standalone SBOM generator—use CycloneDX Python or Jake for that instead.

Install

cyclonedx-python-lib on PyPI

Before you install

Low friction install with five straightforward runtime dependencies. Actively maintained as of 2026-08-13 with no known vulnerabilities and production-stable status.

Requires Python 3.9 or later; does not support Python 2 or versions below 3.9.

License in practice

Apache 2.0 permissive license allows free use, modification, and redistribution with minimal restrictions—suitable for both open-source and proprietary projects.

Quickstart

pip install cyclonedx-python-lib

from cyclonedx.model import Component, ComponentType
from cyclonedx.output import make_outputter

component = Component(name="example", version="1.0", component_type=ComponentType.LIBRARY)
outputter = make_outputter(component, output_format="json")
print(outputter.output_as_string())

Verify before relying

  • Whether the library supports all CycloneDX specification versions or only recent ones
  • Performance characteristics when handling very large BOMs with thousands of components
  • Specific validation rules enforced by the validators beyond standard CycloneDX compliance

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release <4.0,>=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
5 packages
license-expressionpackageurl-pythonpy-serializablesortedcontainerstyping_extensions
MaintenanceActively maintained 1 days since the last release
Last repo commit
First released
Downloads35,721,532 / month, #742 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: Information TechnologyIntended Audience :: Legal IndustryIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software DevelopmentTopic :: System :: Software DistributionTyping :: Typed

Evidence: cyclonedx_python_lib-11.12.0-py3-none-any.whl

Tags

Capabilities
cyclonedx bill of materials librarysbom generation pythonbom data modelssoftware supply chain transparencycyclonedx document creationpurl packageurl handlingvex vdr document support
Topics
sbomsupply-chain-securitybom-generation
PyPI keywords
CycloneDXlibraryOWASPSCASoftware Bill of MaterialsBill of MaterialsBOMSBOMVEXVDROBOMMBOMSaaSBOMSPDXPackageURLPURL

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “cyclonedx bill of materials library”

  • cyclonedx-python-libProvides data models, validators, and serialization tools to create,…
  • cyclonedx-pyGenerates Software Bill of Materials (SBOM) documents in CycloneDX…
  • lib4sbomLib4sbom parses and generates Software Bill of Materials (SBOMs) in…

Give your agent the search over MCP, or paste the wish link into any chat.

More Software Development packages

typing-extensions Worth it
PyPI · Software Development · released Jul 2026

Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.

PSF-2.0pure Python · 3.9+
1.9Bdownloads / mo
numpy Worth it
PyPI · Software Development · released Aug 2026

NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.

BSD-3-Clause AND 0BSD AND MIT AND Zlib AND CC0-1.0compiled wheel · 3.12+
1.1Bdownloads / mo
fastapi Worth it
PyPI · Software Development · released Jul 2026

FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.

MITpure Python · 3.10+
568.6Mdownloads / mo
annotated-doc With conditions
PyPI · Software Development · released Jul 2026

Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.

MITpure Python · 3.9+
456.2Mdownloads / mo
typer Worth it
PyPI · Software Development · released Aug 2026

Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.

Install it if you are building CLIs in Python.

MITpure Python · 3.10+
369.3Mdownloads / mo
distlib With conditions
PyPI · Software Development · released Jun 2026

Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.

permissive licensepure Python
323.3Mdownloads / mo

See also cyclonedx-bom · lib4vex · cyclonedx-py · distro2sbom · lib4sbom · spdx-python-model · spdx-tools · emmet-core · socketdev · py-serializable