macOS
brew install bomctllocal Homebrew formula metadata
brew
Format-agnostic SBOM tooling for the stages between SBOM generation and analysis. Version 0.4.3 via Homebrew; verified 2026-07-05. Also installable with apk: sudo apk add bomctl.
install
brew install bomctllocal Homebrew formula metadata
sudo apk add bomctlAlpine Linux edge package indexes · bomctl · source: dl-cdn.alpinelinux.org
sudo zypper install bomctlopenSUSE Tumbleweed package metadata · bomctl · source: download.opensuse.org
overview
Format-agnostic SBOM tooling for the stages between SBOM generation and analysis
history
bomctl is experimental, format-agnostic SBOM tooling intended to bridge the gap between SBOM generation and SBOM analysis tools.
The GitHub repository was created in January 2024. The README identifies bomctl as an OpenSSF Sandbox project under active development and says it builds on protobom for an SBOM-agnostic component graph.
The project documents installation through a Homebrew tap, container images on Docker Hub, and source builds, and the supplied package facts show availability through Homebrew, apk, and zypper.
Users fetch, import, list, alias, merge, tag, export, and push SBOMs. bomctl stores SBOMs in a persistent cache and can fetch over HTTPS, OCI, Git, GitHub, and GitLab.
bomctl is interesting to package and supply-chain users because it treats SBOMs as package-like artifacts that can be cached, transformed, pushed, and moved between SPDX, CycloneDX, and related ecosystems.
security posture
No matching local secret-handling manifest was found for bomctl. Nucleus package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Credential-bearing paths to review before unattended agent runs.
~/.netrcexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
bomctl | cli | global executable |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
https://github.com/bomctl/bomctl
install metadata
| Package key | brew:bomctl |
|---|---|
| Version | 0.4.3 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/bomctl |
| Homepage | https://github.com/bomctl/bomctl |
| Repository | https://github.com/bomctl/bomctl |
| Upstream docs | https://github.com/bomctl/bomctl#readme |
| License | Apache-2.0 |
| Source archive | https://github.com/bomctl/bomctl/archive/refs/tags/v0.4.3.tar.gz |
| Last updated | 2026-07-05T10:30:30Z |
| Pulse | updated |
| Build dependencies | go |
| Bottle | available (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | bomctl |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
bomctl 0.1.9-r16
Format agnostic SBOM tooling
https://github.com/bomctl/bomctl
sudo apk add bomctlbomctl-bash-completion 0.1.9-r16
Bash completions for bomctl
https://github.com/bomctl/bomctl
sudo apk add bomctl-bash-completionbomctl-fish-completion 0.1.9-r16
Fish completions for bomctl
https://github.com/bomctl/bomctl
sudo apk add bomctl-fish-completionbomctl-zsh-completion 0.1.9-r16
Zsh completions for bomctl
https://github.com/bomctl/bomctl
sudo apk add bomctl-zsh-completionbomctl 0.4.3-1.4
Format agnostic SBOM tooling
https://github.com/bomctl/bomctl
sudo zypper install bomctlbomctl-bash-completion 0.4.3-1.4
Bash Completion for bomctl
https://github.com/bomctl/bomctl
sudo zypper install bomctl-bash-completionbomctl-fish-completion 0.4.3-1.4
Fish Completion for bomctl
https://github.com/bomctl/bomctl
sudo zypper install bomctl-fish-completionbomctl-zsh-completion 0.4.3-1.4
Zsh Completion for bomctl
https://github.com/bomctl/bomctl
sudo zypper install bomctl-zsh-completionsource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.