$npx skillfedfor your agent

distro2sbom

SBOM generator for system distribution

Worth itPyPI Quality AssuranceReleased Apr 2025108.9K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — distro2sbom-0.6.0-py2.py3-none-any.whl
v0.6.0 · released 2025-04-21 · Python >=3.7 · 1 runtime deps: lib4sbom

Yes. The package fills a clear need for SBOM generation across multiple distribution types with low install friction, active maintenance, no known vulnerabilities, and a permissive license. It is suitable for security-conscious teams building CI/CD pipelines or conducting supply chain audits. The Alpha status and modest download volume suggest it is not yet widely adopted, so verify compatibility with your specific distribution and use case before production deployment.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.7 or later; tool relies on system package managers (rpm, dpkg, etc.) being present and accessible for the target distribution type.
  • Low friction installation with a single runtime dependency (lib4sbom).
  • Active maintenance with recent commits and regular releases since initial launch.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for most deployment contexts.

last release 2025-04-21 (480 days) · last repo commit 2026-06-25 · 41 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 108,922 downloads/mo, #12,534 on PyPI

Verify before relying

pip install distro2sbom

distro2sbom --system --sbom spdx --format json -o sbom.json
  • Actual performance and completeness when scanning large system installations with thousands of packages.
  • Compatibility and accuracy across all supported distribution types (rpm, deb, windows, freebsd) in production environments.
  • Whether lib4sbom dependency introduces additional system-level requirements or constraints.
Same gist for agents: .md · .json

What it is and what it does

Distro2sbom is a command-line tool that scans system package managers or input files to generate standardized SBOMs in SPDX or CycloneDX format. It works by querying installed distributions (rpm, deb, windows, freebsd, or auto-detected) and extracting package metadata, then serializing the results as JSON, YAML, or tag-value output. The tool is designed for integration into CI/CD pipelines to maintain auditable records of software components and versions used in deployments.

The package depends on lib4sbom for SBOM generation and serialization. It supports scanning either a specific installed package, all packages on a running system, or a pre-generated package list from a file. Metadata like product name, version, author, and component type can be customized via command-line flags. The tool is classified as Alpha and actively maintained, with support for modern Python versions (3.7 through 3.11).

Use it for

  • Generate SBOMs for CI/CD pipelines to track software components and versions deployed in production systems.
  • Audit installed packages on a running system to support compliance and security reviews.
  • Convert distribution package lists (rpm -qa, dpkg -l output) into standardized SBOM formats for supply chain analysis.
  • Create SBOMs for containerized or virtualized environments to document all dependencies at deployment time.
  • Support vulnerability tracking workflows by maintaining versioned records of all installed components.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The package fills a clear need for SBOM generation across multiple distribution types with low install friction, active maintenance, no known vulnerabilities, and a permissive license. It is suitable for security-conscious teams building CI/CD pipelines or conducting supply chain audits. The Alpha status and modest download volume suggest it is not yet widely adopted, so verify compatibility with your specific distribution and use case before production deployment.

Install

distro2sbom on PyPI

Before you install

Low friction installation with a single runtime dependency (lib4sbom). Active maintenance with recent commits and regular releases since initial launch.

Requires Python 3.7 or later; tool relies on system package managers (rpm, dpkg, etc.) being present and accessible for the target distribution type.

License in practice

Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for most deployment contexts.

Quickstart

pip install distro2sbom

distro2sbom --system --sbom spdx --format json -o sbom.json

Verify before relying

  • Actual performance and completeness when scanning large system installations with thousands of packages.
  • Compatibility and accuracy across all supported distribution types (rpm, deb, windows, freebsd) in production environments.
  • Whether lib4sbom dependency introduces additional system-level requirements or constraints.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.7
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
lib4sbom
MaintenanceActively maintained 480 days since the last release
Last repo commit
First released
Downloads108,922 / month, #12,534 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy

Evidence: distro2sbom-0.6.0-py2.py3-none-any.whl

Tags

Capabilities
SBOM generatorsoftware bill of materialsSPDX CycloneDX exportsystem package inventorydistribution SBOMsupply chain securitypackage dependency audit
Topics
sbom-generationsupply-chain-securitydevops
PyPI keywords
securitytoolsSBOMDevSecOpsSPDXCycloneDXDistributions

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “SPDX CycloneDX export”

  • distro2sbomGenerates a Software Bill of Materials (SBOM) for installed packages…
  • socketdevA Python SDK that wraps the Socket.dev REST API, enabling…
  • lib4sbomLib4sbom parses and generates Software Bill of Materials (SBOMs) in…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also lib4sbom · cyclonedx-bom · cyclonedx-py · cyclonedx-python-lib · bindep · socketdev · spdx-tools · scancode-toolkit · lib4vex · csaf-tool