Skip to main content

Compliance Assistant

OpenRail Administrative Project Test suites REUSE status The latest version of Compliance Assistant can be found on PyPI. Information on what versions of Python Compliance Assistant supports can be found on PyPI.

Compliance Assistant is a comprehensive toolset designed to assist with creating and managing Software Bill of Materials (SBOMs). It helps in enriching SBOMs with licensing and copyright information and checks for Open Source license compliance using data from ClearlyDefined.

Features

  • SBOM Generation: Automatically generate a CycloneDX SBOM from a specified code repository.
  • SBOM Enrichment: Enhance an existing SBOM with detailed licensing and copyright information using ClearlyDefined data.
  • SBOM Parsing: Extract specific information from a CycloneDX SBOM.
  • License and Copyright Information Retrieval: Fetch licensing and copyright details for a single package from ClearlyDefined.
  • License compliance support: Extract and unify licenses from SBOM, suggest possible license outbound candidates

Some of these features are made possible by excellent programs such as flict, cdxgen and syft.

Requirements

  • Python 3.10+
  • Internet connection for accessing ClearlyDefined services
  • At least one SBOM generator:

Installation

pipx makes installing and running Python programs easier and avoids conflicts with other packages. Install it with

pip3 install pipx

The following one-liner both installs and runs this program from PyPI:

pipx run compliance-assistant

If you want to be able to use compliance-assistant without prepending it with pipx run every time, install it globally like so:

pipx install compliance-assistant

compliance-assistant will then be available in ~/.local/bin, which must be added to your $PATH.

After this, make sure that ~/.local/bin is in your $PATH. On Windows, the required path for your environment may look like %USERPROFILE%\AppData\Roaming\Python\Python310\Scripts, depending on the Python version you have installed.

To upgrade compliance-assistant to the newest available version, run this command:

pipx upgrade compliance-assistant

Other installation methods

You may also use pure pip or uv to install this package.

Usage

The Compliance Assistant provides multiple commands to facilitate different tasks. Each command is invoked through the compliance-assistant command-line interface with specific options.

Depending on your exact installation method, this may be one of

# Run via pipx
pipx run compliance-assistant
# Installation via pipx or pip
compliance-assistant
# Run via uv
uv run compliance-assistant

In the following, we will just use compliance-assistant.

Command Structure

compliance-assistant <command> [<subcommand>] [subcommand-options]

Commands

Please run compliance-assistant --help to get an overview of the commands and global options.

For each command, you can get detailed options, e.g., compliance-assistant sbom enrich --help.

Examples

  • Create an SBOM for the current directory using syft: compliance-assistant sbom generate -g syft -d . -o /tmp/my-sbom.json
  • Enrich an SBOM with ClearlyDefined data: compliance-assistant sbom enrich -f /tmp/my-sbom.json -o /tmp/my-enriched-sbom.json
  • Extract certain data from an SBOM: compliance-assistant sbom parse -f /tmp/my-enriched-sbom.json -e purl,copyright,name
  • Gather ClearlyDefined licensing/copyright information for one package: compliance-assistant clearlydefined fetch -p pkg:pypi/inwx-dns-recordmaster@0.3.1
  • Get all licenses found in the enriched SBOM: compliance-assistant licensing list -f /tmp/my-enriched-sbom.json -o plain
  • Get license outbound candidate based on licenses from SBOM: compliance-assistant licensing outbound -f /tmp/my-enriched-sbom.json

Run as GitHub workflow

You may also use GitHub workflows to generate an SBOM regularly, e.g., on each published release:

name: Generate and enrich SBOM

on:
  release:
    types: [published]

jobs:
  # Generate the SBOM with syft and enrich the generated SBOM
  sbom-generate-and-enrich:
    runs-on: ubuntu-22.04
    needs: sbom-gen
    steps:
      # Install compliance-assistant
      - name: Set up Python
        uses: actions/setup-python@v5
        with:
          python-version: "3.12"
          cache: "pip"
      - name: Install compliance-assistant
        run: pip install compliance-assistant
      # Install syft
      - run: mkdir -p ~/.local/bin
      - name: Install syft
        run: curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b ~/.local/bin
      # Generate SBOM with syft via compliance-assistant
      - name: Generate SBOM with syft
        run: compliance-assistant sbom generate -g syft -d . -o ${{ runner.temp }}/sbom-raw.json
      # Enrich SBOM with compliance-assistant
      - name: Enrich SBOM
        run: compliance-assistant sbom enrich -f ${{ runner.temp }}/sbom-raw.json -o ${{ runner.temp }}/sbom-enriched.json
      # Upload enriched SBOM as artifact
      - name: Store enriched SBOM as artifact
        uses: actions/upload-artifact@v4
        with:
          name: sbom-enriched
          path: ${{ runner.temp }}/sbom-enriched.json

Development and Contribution

We welcome contributions to improve Compliance Assistant. Please read CONTRIBUTING.md for all information.

License

The content of this repository is licensed under the Apache 2.0 license.

There may be components under different, but compatible licenses or from different copyright holders. The project is REUSE compliant which makes these portions transparent. You will find all used licenses in the LICENSES directory.

The project has been started by the OpenRail Association. You are welcome to contribute!

Metadata

Release files for compliance-assistant 1.1.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for compliance-assistant 1.1.8
File Size Uploaded
compliance_assistant-1.1.8.tar.gz 30.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for compliance-assistant 1.1.8
File Interpreter ABI Platform
compliance_assistant-1.1.8-py3-none-any.whl Python 3 none any Details

Total release size: 67.8 kB

Release files / compliance_assistant-1.1.8.tar.gz

Download URL compliance_assistant-1.1.8.tar.gz
Size 30.0 kB
Tags Source
SHA-256 checksum
How to use checksums
48f036de465621651056c26724712c2f9af982b21bc642935706298d57401d25
BLAKE2b-256 checksum
How to use checksums
8dd38ea8c6caf28cf828bc6dfbc496020438915d4688f1120f24153ed840bb40
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release files / compliance_assistant-1.1.8-py3-none-any.whl

Download URL compliance_assistant-1.1.8-py3-none-any.whl
Size 37.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3a1e952e023981096434b5413874c9c07bb478d380560bc83273f49079d78b3e
BLAKE2b-256 checksum
How to use checksums
ef7ecb241c14a7886b9eaf2ff60cdd2a79e756eed478c63938ae8ac3a0927172
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.1.8 This release

2 release files

1.1.7

2 release files

1.1.6

2 release files

1.1.5

2 release files

1.1.4

2 release files

1.1.3

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page