Skip to main content

Tool for creating, modifying and validating CycloneDX SBOMs.

Project description

build and test security: bandit Code style: black Checked with mypy Imports: isort Static Badge

CycloneDX Editor/Validator

This command-line tool performs various actions on CycloneDX SBOMs. It allows you to modify, merge and validate your Software Bill of Materials (SBOM).

The tool is built with automation in mind, i.e. usage within CI/CD. We try to be as scriptable as possible with various command-line flags, avoiding interactive prompts, providing multiple output options and fine-grained exit codes.

Command overview

Command Description
amend Accepts a single input file and will apply one or multiple operations to it. Each operation modifies certain aspects of the SBOM. These modifications cannot be targeted at individual components in the SBOM which sets the amend command apart from set. Its use-case is ensuring an SBOM fulfils certain requirements in an automated fashion.
build-public Creates a redacted version of an SBOM fit for publication.
merge Merges two or more CycloneDX documents into one.
merge-vex [Deprecated] Merges the vex information in two or more CycloneDX documents into one.
set Sets properties on specified components to specified values. If a component in an SBOM is missing a particular property or the property is present but has a wrong value, this command can be used to modify just the affected properties without changing the rest of the SBOM.
validate Validate the SBOM against a built-in or user-provided JSON schema.

Installation and usage

This tool is published on PyPi.

For detailed installation and usage guides, please refer to our official documentation.

Contributing

See our contribution guidelines.

License

This software is made available under the GNU General Public License v3 (GPL-3.0-or-later).

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cyclonedx_editor_validator-0.18.2.tar.gz (272.8 kB view details)

Uploaded Source

Built Distribution

cyclonedx_editor_validator-0.18.2-py3-none-any.whl (294.6 kB view details)

Uploaded Python 3

File details

Details for the file cyclonedx_editor_validator-0.18.2.tar.gz.

File metadata

  • Download URL: cyclonedx_editor_validator-0.18.2.tar.gz
  • Upload date:
  • Size: 272.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.8.3 CPython/3.10.12 Linux/6.5.0-1025-azure

File hashes

Hashes for cyclonedx_editor_validator-0.18.2.tar.gz
Algorithm Hash digest
SHA256 bf9251eb310f480e17aa3ca40e7eb6cb3e05186cb644f47734c3eefb33673b73
MD5 5d98575515db845a61fd2ece2f3cbe27
BLAKE2b-256 708dc7144f11bf27b62c70628a7aa3f2787d3177e7f15fb4483a30a38e8fe3c4

See more details on using hashes here.

File details

Details for the file cyclonedx_editor_validator-0.18.2-py3-none-any.whl.

File metadata

File hashes

Hashes for cyclonedx_editor_validator-0.18.2-py3-none-any.whl
Algorithm Hash digest
SHA256 a1c628c028862957ef35a7119296eada3251e75b2a3dc01ac54b01096c9a45b0
MD5 c5669f458a7ee563a01960369b2a8601
BLAKE2b-256 d635b3d6c2a8012917b4f7f106df416825d4b2264c48f0b45bb329e7dde9bc4e

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page