# Install bomctl with Homebrew, apk, zypper

Format-agnostic SBOM tooling for the stages between SBOM generation and analysis. Version 0.4.3 via Homebrew; verified 2026-07-05. Also installable with apk: sudo apk add bomctl.

## Install

```sh
sudo av install brew:bomctl
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install bomctl
```

  Evidence: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add bomctl
```

  Evidence: Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz

- zypper (92%):

```sh
sudo zypper install bomctl
```

  Evidence: openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst

## Package facts

- **Package key:** brew:bomctl
- **Package manager:** Homebrew
- **Package manager page:** <https://formulae.brew.sh/formula/bomctl>
- **Version:** 0.4.3
- **Source summary:** Format-agnostic SBOM tooling for the stages between SBOM generation and analysis
- **Homepage:** <https://github.com/bomctl/bomctl>
- **Repository:** <https://github.com/bomctl/bomctl>
- **Upstream docs:** <https://github.com/bomctl/bomctl#readme>
- **License:** Apache-2.0
- **Source archive:** <https://github.com/bomctl/bomctl/archive/refs/tags/v0.4.3.tar.gz>
- **Last updated:** 2026-07-05T10:30:30Z
- **Generated:** 2026-07-25T07:20:51+00:00

## Executables

- bomctl (cli)
- bomctl (alias)

## Build dependencies

- go

## Install behavior

- Post-install hook: not defined
- Bottle: available on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## Freshness

- Page generated: 2026-07-25
- Package-manager version: 0.4.3
- Package-manager updated: 2026-07-05
- Local data: ok
- Upstream repository: https://github.com/bomctl/bomctl
- Upstream latest detected: v0.4.3 (current)
## Project history and usage

bomctl is experimental, format-agnostic SBOM tooling intended to bridge the gap between SBOM generation and SBOM analysis tools.

### Project history

The GitHub repository was created in January 2024. The README identifies bomctl as an OpenSSF Sandbox project under active development and says it builds on protobom for an SBOM-agnostic component graph.

### Adoption history

The project documents installation through a Homebrew tap, container images on Docker Hub, and source builds, and the supplied package facts show availability through Homebrew, apk, and zypper.

### How it is used

Users fetch, import, list, alias, merge, tag, export, and push SBOMs. bomctl stores SBOMs in a persistent cache and can fetch over HTTPS, OCI, Git, GitHub, and GitLab.

### Why package nerds care

bomctl is interesting to package and supply-chain users because it treats SBOMs as package-like artifacts that can be cached, transformed, pushed, and moved between SPDX, CycloneDX, and related ecosystems.

### Timeline

- 2024: GitHub repository created.
- 2024: v0.1.0-alpha appears in GitHub releases.
- 2025: v0.4.3 appears in GitHub releases.

### Related projects

- protobom, OpenSSF, SPDX, CycloneDX, GUAC, Sigstore

### Sources

- <https://api.github.com/repos/bomctl/bomctl>
- <https://github.com/bomctl/bomctl#readme>
- <https://github.com/bomctl/bomctl/tree/main/docs/architecture>


## Security Notes

No matching local secret-handling manifest was found for bomctl. Nucleus package metadata is still published here so future coverage has a stable package URL.



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: ~/.netrc
## Source Database Details

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** bomctl
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable

## Other Package-Manager Records

- apk - bomctl - 0.1.9-r16: normalized package name match | Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Format agnostic SBOM tooling | https://github.com/bomctl/bomctl
- apk - bomctl-bash-completion - 0.1.9-r16: normalized package name match | Alpine Linux edge package indexes: bomctl-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Bash completions for bomctl | https://github.com/bomctl/bomctl
- apk - bomctl-fish-completion - 0.1.9-r16: normalized package name match | Alpine Linux edge package indexes: bomctl-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Fish completions for bomctl | https://github.com/bomctl/bomctl
- apk - bomctl-zsh-completion - 0.1.9-r16: normalized package name match | Alpine Linux edge package indexes: bomctl-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Zsh completions for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl - 0.4.3-1.4: normalized package name match | openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst | Format agnostic SBOM tooling | https://github.com/bomctl/bomctl
- zypper - bomctl-bash-completion - 0.4.3-1.4: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst | Bash Completion for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl-fish-completion - 0.4.3-1.4: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst | Fish Completion for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl-zsh-completion - 0.4.3-1.4: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst | Zsh Completion for bomctl | https://github.com/bomctl/bomctl


## Related links

- [Source-control packages](https://www.automicvault.com/pkg/source-control-tools/) - Belongs to a source-control command family.
- [Terminal utility packages](https://www.automicvault.com/pkg/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Text processing packages](https://www.automicvault.com/pkg/text-processing-tools/) - Matched text, document, or structured-data processing metadata.
- [Networking and protocol packages](https://www.automicvault.com/pkg/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [go](https://www.automicvault.com/pkg/brew/go/) - Build dependency declared by Homebrew.
- [cyclonedx-gomod](https://www.automicvault.com/pkg/brew/cyclonedx-gomod/) - Shares av.db curated category or tags: cli, cyclonedx, sbom, security, software-supply-chain.
- [cyclonedx-npm](https://www.automicvault.com/pkg/brew/cyclonedx-npm/) - Shares av.db curated category or tags: cli, cyclonedx, sbom, security, software-supply-chain.
- [cyclonedx-python](https://www.automicvault.com/pkg/brew/cyclonedx-python/) - Shares av.db curated category or tags: cli, cyclonedx, sbom, security, software-supply-chain.
- [cdxgen](https://www.automicvault.com/pkg/brew/cdxgen/) - Shares av.db curated category or tags: cli, cyclonedx, sbom, security, software-supply-chain.
- [cyclonedx-cli](https://www.automicvault.com/pkg/brew/cyclonedx-cli/) - Shares av.db curated category or tags: cli, cyclonedx, sbom, security, software-supply-chain.
- [sbom-tool](https://www.automicvault.com/pkg/brew/sbom-tool/) - Shares av.db curated category or tags: cli, sbom, security, software-supply-chain.
- [bom](https://www.automicvault.com/pkg/brew/bom/) - Shares av.db curated category or tags: cli, sbom, security, software-supply-chain, spdx.
- [chainloop-cli](https://www.automicvault.com/pkg/brew/chainloop-cli/) - Shares av.db curated category or tags: cli, sbom, security, software-supply-chain.

## Combined YAML source

View the package source record on GitHub. [combined/bomctl.yml](https://github.com/automic-vault/db/blob/main/combined/bomctl.yml)


## Sources

- Nucleus package database
- package-page enrichment
- curated configuration and credential file locations
- curated package history
- package version freshness
- av.db category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
