cyclonedx-python-lib
Python library for CycloneDX
Decision gist · record as of 2026-08-14
Yes. This is a production-stable, actively maintained library with no known vulnerabilities, low install friction, and permissive licensing. Install it if you are building tooling that needs to create, read, or validate CycloneDX documents; do not install it as a standalone SBOM generator—use CycloneDX Python or Jake for that instead.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; does not support Python 2 or versions below 3.9.
- Low friction install with five straightforward runtime dependencies.
- Actively maintained as of 2026-08-13 with no known vulnerabilities and production-stable status.
License · maintenance · safety
Apache-2.0 (permissive) — Apache 2.0 permissive license allows free use, modification, and redistribution with minimal restrictions—suitable for both open-source and proprietary projects.
last release 2026-08-13 (1 days) · last repo commit 2026-08-13 · 113 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 35,721,532 downloads/mo, #742 on PyPI
Alternatives
Verify before relying
pip install cyclonedx-python-lib
from cyclonedx.model import Component, ComponentType
from cyclonedx.output import make_outputter
component = Component(name="example", version="1.0", component_type=ComponentType.LIBRARY)
outputter = make_outputter(component, output_format="json")
print(outputter.output_as_string())- Whether the library supports all CycloneDX specification versions or only recent ones
- Performance characteristics when handling very large BOMs with thousands of components
- Specific validation rules enforced by the validators beyond standard CycloneDX compliance
What it is and what it does
CycloneDX Python Library is a data-modeling and validation toolkit for working with CycloneDX Bill of Materials documents. It provides Python classes and methods to construct, validate, and serialize BOM structures that describe software components, services, hardware, and AI elements—enabling teams to document supply-chain composition and track dependencies for security and compliance purposes.
The library is designed as a foundation for other tools rather than a standalone application. It handles the low-level mechanics of BOM creation and rendering: defining component types, managing dependencies, encoding metadata like PackageURLs and license expressions, and outputting to standard formats. Teams building SBOM generators, vulnerability disclosure tools (VEX/VDR), or supply-chain analysis platforms typically use this library as their core data layer.
Use it for
- Building custom SBOM generation tools that need to programmatically create and validate CycloneDX documents
- Integrating BOM generation into CI/CD pipelines to automatically track software composition
- Parsing and transforming existing CycloneDX BOMs for compliance reporting or supply-chain audits
- Embedding BOM support into package managers or dependency analysis tools
- Creating VEX or VDR documents to communicate vulnerability and remediation information
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is a production-stable, actively maintained library with no known vulnerabilities, low install friction, and permissive licensing. Install it if you are building tooling that needs to create, read, or validate CycloneDX documents; do not install it as a standalone SBOM generator—use CycloneDX Python or Jake for that instead.
Install
cyclonedx-python-lib on PyPI
Before you install
Low friction install with five straightforward runtime dependencies. Actively maintained as of 2026-08-13 with no known vulnerabilities and production-stable status.
Requires Python 3.9 or later; does not support Python 2 or versions below 3.9.
License in practice
Apache 2.0 permissive license allows free use, modification, and redistribution with minimal restrictions—suitable for both open-source and proprietary projects.
Quickstart
pip install cyclonedx-python-lib
from cyclonedx.model import Component, ComponentType
from cyclonedx.output import make_outputter
component = Component(name="example", version="1.0", component_type=ComponentType.LIBRARY)
outputter = make_outputter(component, output_format="json")
print(outputter.output_as_string())
Verify before relying
- Whether the library supports all CycloneDX specification versions or only recent ones
- Performance characteristics when handling very large BOMs with thousands of components
- Specific validation rules enforced by the validators beyond standard CycloneDX compliance
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release <4.0,>=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 5 packageslicense-expressionpackageurl-pythonpy-serializablesortedcontainerstyping_extensions |
| Maintenance | Actively maintained 1 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 35,721,532 / month, #742 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: Information TechnologyIntended Audience :: Legal IndustryIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software DevelopmentTopic :: System :: Software DistributionTyping :: Typed |
Evidence: cyclonedx_python_lib-11.12.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “cyclonedx bill of materials library”
- cyclonedx-python-libProvides data models, validators, and serialization tools to create,…
- cyclonedx-pyGenerates Software Bill of Materials (SBOM) documents in CycloneDX…
- lib4sbomLib4sbom parses and generates Software Bill of Materials (SBOMs) in…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also cyclonedx-bom · lib4vex · cyclonedx-py · distro2sbom · lib4sbom · spdx-python-model · spdx-tools · emmet-core · socketdev · py-serializable