Automic VaultAutomic Vault

brew

cyclonedx-npm を Homebrew でインストール

cyclonedx-npm のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install cyclonedx-npm

local Homebrew formula metadata

概要

パッケージ概要

Creates CycloneDX Software Bill of Materials (SBOM) from npm projects

コマンドとエイリアス

  • cyclonedx-npm

履歴

プロジェクトの歴史と使われ方

CycloneDX SBOM for npm is the CycloneDX project's command-line generator for producing CycloneDX Software Bill of Materials documents from Node.js npm projects.

プロジェクトの歴史

The project reached its first feature-complete beta in August 2022 and its first major release in September 2022. Its early releases focused on npm and npx execution, Windows usability, lock-file behavior, PackageURL output, and npm version compatibility.

The 1.x series added SBOM validation, richer package evidence, CycloneDX specification support through 1.5, SCVS-oriented improvements, npm 10 and npm 11 support, workspace handling, and license-text gathering. Later major releases raised runtime requirements, changed default specification behavior, improved PackageURL generation, and addressed security issues in npm execution and workspace handling.

採用の歴史

The official README documents installation as a global npm tool, via npx, or as a project development dependency, which places it directly in normal Node.js package-manager workflows.

CycloneDX Tool Center lists CycloneDX for NPM as an open-source tool for JavaScript and Node.js across design, pre-build, build, post-build, and operations lifecycle phases. The supplied Homebrew input also shows it is packaged as the Homebrew formula cyclonedx-npm.

使われ方

The CLI defaults to reading package.json in the current project and can emit JSON or XML CycloneDX BOMs to stdout or to a selected output file. It can omit dependency classes, select workspaces, gather license text evidence, flatten components, choose a CycloneDX spec version, request reproducible output, and validate generated BOMs.

The official docs explain that the tool uses npm-ls against the target project and interprets npm's output, with package.json files inside node_modules used as an additional evidence source when needed.

パッケージ好きにとっての重要性

For package maintainers and release engineers, cyclonedx-npm matters because it turns npm's installed dependency graph and package metadata into a portable SBOM artifact that can be checked into release pipelines, handed to vulnerability-management systems, or shared with downstream consumers.

It sits at the intersection of npm, PackageURL, CycloneDX, and Homebrew packaging: the tool is itself distributed through package managers while producing package-centric metadata for supply-chain security workflows.

タイムライン

  • 2022-08-20: First feature-complete implementation appeared as 1.0.0-beta.1.
  • 2022-09-24: First major version, 1.0.0, was released.
  • 2022-11-05: Support for npm v9 was enabled.
  • 2023-05-17: Version 1.12.0 added SCVS SBOM criteria-oriented improvements.
  • 2023-07-07: Version 1.13.0 added CycloneDX Specification 1.5 support.
  • 2025-01-27: Version 2.0.0 changed the default CycloneDX spec version to 1.6.
  • 2025-04-08: Version 3.0.0 dropped support for Node.js below 20.18.0 and npm below 9.
  • 2026-07-07: Version 6.0.0 fixed a workspace shell-injection vulnerability on Windows and reworked npm detection and handling.

Related projects

  • CycloneDX is the underlying SBOM standard and OWASP project; TC54's official history records CycloneDX v1.0 in 2018 and ECMA-424 standardization in 2024.
  • The tool depends on the CycloneDX JavaScript library to build, serialize, and validate BOM data structures, and it is related to the wider CycloneDX family of package-ecosystem SBOM generators.

セキュリティ状態

保護ツール対応はまだ見つかっていません

cyclonedx-npm に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 1 個のプラットフォームターゲットで利用できます。
  • 1 件の実行時依存関係とともにインストールされます。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
cyclonedx-npmcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版6.0.0
マネージャ更新日2026-07-13
ローカルデータOK
上流not checked
検出された最新未検出

https://github.com/CycloneDX/cyclonedx-node-npm

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:cyclonedx-npm
バージョン6.0.0
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/cyclonedx-npm
ホームページhttps://github.com/CycloneDX/cyclonedx-node-npm
リポジトリhttps://github.com/CycloneDX/cyclonedx-node-npm
上流ドキュメントhttps://cyclonedx.org/tool-center
ライセンスApache-2.0
ソースアーカイブhttps://registry.npmjs.org/@cyclonedx/cyclonedx-npm/-/cyclonedx-npm-6.0.0.tgz
最終更新2026-07-13T03:36:27Z
Pulseupdated
依存関係node
Bottle利用可能 (対象 all)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namecyclonedx-npm
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment