Automic VaultAutomic Vault

brew

cyclonedx-python mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für cyclonedx-python in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install cyclonedx-python

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#cyclonedx-python

nixpkgs package indexes · pkgs/by-name/cy/cyclonedx-python/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Creates CycloneDX Software Bill of Materials (SBOM) from Python projects

Befehle und Aliase

  • cyclonedx-py

Verlauf

Projektgeschichte und Nutzung

CycloneDX Python is the official CycloneDX SBOM generator for Python projects, manifests, lockfiles, requirements files, and environments.

Projektgeschichte

The cyclonedx-python repository was created in November 2018, shortly after CycloneDX v1.0 introduced a security-focused BOM format. Over time the tool grew from Python dependency SBOM generation into a broader Python packaging surface covering virtual environments, requirements.txt, Poetry, and Pipenv, with older versions retaining support for Python 2.7 while current releases require Python 3.9 or newer.

Adoptionsgeschichte

The README points users to PyPI, pipx, Poetry, uv, Docker, and documentation, and the official tool center lists CycloneDX for Python as an open-source generator. That broad packaging footprint matters because Python SBOMs are often needed from whatever artifact a project already has: an environment, a lockfile, or a requirements file.

Wie es verwendet wird

The cyclonedx-py command generates SBOMs from Python virtual environments, requirements files, Pipenv projects, and Poetry projects. It uses CycloneDX Python libraries for data structures, serialization, and validation while keeping its own public surface centered on the CLI.

Warum Paket-Nerds sich dafür interessieren

For package nerds, cyclonedx-python is where Python packaging diversity meets SBOM standardization: it has to interpret several Python dependency sources while producing a single CycloneDX document suitable for CI, auditing, and vulnerability tooling.

Zeitleiste

  • 2018: Repository created after the first CycloneDX specification release.
  • 2021: v1.x releases were published under the CycloneDX Python tool line.
  • 2024: CycloneDX v1.6 became ECMA-424, increasing the standardization backdrop for generators.
  • 2026: v7.x releases continued support for current Python environments and project formats.

Related projects

  • The tool uses the CycloneDX Python library and complements cyclonedx-cli and other language-specific generators in the CycloneDX project.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für cyclonedx-python wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Installiert mit 2 Laufzeitabhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
cyclonedx-pycliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version7.3.1
Manager aktualisiert2026-07-24
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://cyclonedx.org/

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:cyclonedx-python
Version7.3.1
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/cyclonedx-python
Homepagehttps://cyclonedx.org/
Repositoryhttps://github.com/CycloneDX/cyclonedx-python
Upstream-Dokumentationhttps://cyclonedx-bom-tool.readthedocs.io/
LizenzApache-2.0
Quellarchivhttps://files.pythonhosted.org/packages/c7/a2/ab75601071afb20352758ef20fd7983cd290f807cabd672eaa28eed45018/cyclonedx_bom-7.3.1.tar.gz
Zuletzt aktualisiert2026-07-24T15:03:48Z
Pulseupdated
Abhängigkeitenpython@3.14, rpds-py
Von macOS bereitgestellte Bibliothekenlibxml2, libxslt
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namecyclonedx-python
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

cyclonedx-python

nix profile install nixpkgs#cyclonedx-python
  • normalized package name match
  • Abgeglichen nach: Cyclonedx Python
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/cy/cyclonedx-python/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment