csspin-tooling is maintained by CONTACT Software GmbH and provides utility plugins and tasks to be used with the csspin task runner.
The following plugins are available:
csspin_tooling.sbomasm: Assembles multiple CycloneDX SBOM files into a single enriched top-level SBOM using the sbomasm tool.
csspin_tooling.fetch_vex: Downloads a CycloneDX VEX file for a given package version from Dependency-Track.
Prerequisites
csspin must be installed before using this package:
python -m pip install csspin
Using csspin-tooling
Add the package and the desired plugins to your project’s spinfile.yaml:
spin:
project_name: my_project
plugin_packages:
- csspin-python
- csspin-tooling
plugins:
- csspin_tooling.sbomasm
- csspin_tooling.fetch_vex
python:
version: "3.11.9"
Provision the project to download sbomasm and install all dependencies:
spin provision
Assemble a top-level SBOM from all *.cdx.json files in the project root:
spin sbom --help
Metadata
Release files for csspin-tooling 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| csspin_tooling-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Release files / csspin_tooling-1.1.0-py3-none-any.whl
| Download URL | csspin_tooling-1.1.0-py3-none-any.whl |
|---|---|
| Size | 15.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
67ede232a67ea123a953b34f66a4ec1613b17faad92cfb29f8ba99f2c4878dfc
|
|
BLAKE2b-256 checksum How to use checksums |
2dbeaf635500841b9bab2f7d0e241b106988e9cb4745a07dd5a365dd922fccb4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.16
|