CycloneDX Python SBOM Generation Tool
This tool generates Software Bill of material (SBOM) documents in OWASP CycloneDX format.
This is probably the most accurate, complete SBOM generator for any python-related projects.
Supported data sources are:
- Python (virtual) environment
Poetrymanifest and lockfilePipenvmanifest and lockfile- Pip's
requirements.txtformat PDMmanifest and lockfile are not explicitly supported.
However, PDM's Python virtual environments are fully supported. See the docs for an example.uvmanifest and lockfile are not explicitly supported.
However, uv's Python virtual environments are fully supported. See the docs for an example.Condaas a package manager is no longer supported since version 4.
However, conda's Python environments are fully supported via the methods listed above. See the docs for an example.
Based on OWASP Software Component Verification Standard for Software Bill of Materials' criteria, this tool is capable of producing SBOM documents almost passing Level-2 (only signing needs to be done externally).
The resulting SBOM documents follow official specifications and standards,
and might have properties following
cdx:python Namespace Taxonomy,
cdx:pipenv Namespace Taxonomy,
cdx:poetry Namespace Taxonomy
.
Read the full documentation for more details.
Requirements
- Python
>=3.9,<4
However, there are older versions of this tool available, which
support Python >=2.7.
Installation
Install this from Python Package Index (PyPI) using your preferred Python package manager.
install via one of commands:
python -m pip install cyclonedx-bom # install via pip
pipx install cyclonedx-bom # install via pipx
poetry add cyclonedx-bom # install via poetry
uv tool install cyclonedx-bom # install via uv
# ... you get the hang
Usage
Call via one of commands:
cyclonedx-py # call script
python3 -m cyclonedx_py # call python module CLI
Basic usage
$ cyclonedx-py --help
usage: cyclonedx-py [-h] [--version] <command> ...
Creates CycloneDX Software Bill of Materials (SBOM) from Python projects and environments.
positional arguments:
<command>
environment (env, venv)
Build an SBOM from Python (virtual) environment
requirements Build an SBOM from Pip requirements
pipenv Build an SBOM from Pipenv manifest
poetry Build an SBOM from Poetry project
options:
-h, --help show this help message and exit
--version show program's version number and exit
Advanced usage and details
See the full documentation for advanced usage and details on input formats, switches and options.
Python Support
We endeavour to support all functionality for all current actively supported Python versions.
However, some features may not be possible/present in older Python versions due to their lack of support.
However, there are older versions of this tool, that support python>=2.7.
Internals
This tool utilizes the CycloneDX Python library to generate the actual data structures, and serialize and validate them.
This tool does not expose any additional public API or symbols - all code is intended to be internal and might change without any notice during version upgrades. However, the CLI is stable - you might call it programmatically. See the documentation for an example.
Contributing
Feel free to open issues, bugreports or pull requests.
See the CONTRIBUTING file for details, and how to run/setup locally.
Copyright & License
CycloneDX BOM is Copyright (c) OWASP Foundation. All Rights Reserved.
Permission to modify and redistribute is granted under the terms of the Apache 2.0 license.
See the LICENSE file for the full license.
Metadata
Release files for cyclonedx-bom 7.5.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cyclonedx_bom-7.5.0.tar.gz | 4.4 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cyclonedx_bom-7.5.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 4.5 MB
Release files / cyclonedx_bom-7.5.0.tar.gz
| Download URL | cyclonedx_bom-7.5.0.tar.gz |
|---|---|
| Size | 4.4 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
396cc8c9cb7533d25a21f930b45d2699a1839e3ba2be9ba88f8bd61c566b51dc
|
|
BLAKE2b-256 checksum How to use checksums |
028765a331687130bcd70152b345e05b6ec6b81b8d5fb7709e8aab48babcdd32
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / cyclonedx_bom-7.5.0-py3-none-any.whl
| Download URL | cyclonedx_bom-7.5.0-py3-none-any.whl |
|---|---|
| Size | 61.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a3020e225107214a66cb9c79ae83e3a71640a06d4ff3a0e2f9cb0d238f7061fd
|
|
BLAKE2b-256 checksum How to use checksums |
39f64da2674038e1558b93872dc6a3d10172be60db05c5ca9a5e5de73b3edd7e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log