Python library for CycloneDX
Project description
CycloneDX Python Library
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction.
This Python package provides data models, validators and more, to help you create/render/read CycloneDX documents.
This package is not designed for standalone use. It is a software library.
As of version 3.0.0
, the internal data model was adjusted to allow CycloneDX VEX documents to be produced as per
official examples linking VEX to a separate CycloneDX document.
If you're looking for a CycloneDX tool to run to generate (SBOM) software bill-of-materials documents, why not checkout CycloneDX Python or Jake.
Documentation
View the documentation here.
Python Support
We endeavour to support all functionality for all current actively supported Python versions. However, some features may not be possible/present in older Python versions due to their lack of support.
Changelog
See our CHANGELOG.
Contributing
Feel free to open issues, bugreports or pull requests.
See the CONTRIBUTING file for details.
Copyright & License
CycloneDX Python Lib is Copyright (c) OWASP Foundation. All Rights Reserved.
Permission to modify and redistribute is granted under the terms of the Apache 2.0 license.
See the LICENSE file for the full license.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file cyclonedx_python_lib-8.4.0.tar.gz
.
File metadata
- Download URL: cyclonedx_python_lib-8.4.0.tar.gz
- Upload date:
- Size: 1.1 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/5.1.1 CPython/3.12.7
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 1d86efc1e81c0fd01141658b8aed5248c4f4d8d300d7ced9e1dfc39abeafc0a9 |
|
MD5 | c8087cddb2ca42d483148eba2de9370c |
|
BLAKE2b-256 | 5f5e92fbc03f1ab980ccd2b942e3b3cda0c60a5828a673837b4ee1eaceb924a0 |
Provenance
The following attestation bundles were made for cyclonedx_python_lib-8.4.0.tar.gz
:
Publisher:
release.yml
on CycloneDX/cyclonedx-python-lib
-
Statement type:
https://in-toto.io/Statement/v1
- Predicate type:
https://docs.pypi.org/attestations/publish/v1
- Subject name:
cyclonedx_python_lib-8.4.0.tar.gz
- Subject digest:
1d86efc1e81c0fd01141658b8aed5248c4f4d8d300d7ced9e1dfc39abeafc0a9
- Sigstore transparency entry: 144698438
- Sigstore integration time:
- Predicate type:
File details
Details for the file cyclonedx_python_lib-8.4.0-py3-none-any.whl
.
File metadata
- Download URL: cyclonedx_python_lib-8.4.0-py3-none-any.whl
- Upload date:
- Size: 372.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/5.1.1 CPython/3.12.7
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | fd44efd601f651c8865acf0dfeacb0df19a2b50ec69ead0262096fd2f67197b9 |
|
MD5 | f0ae0e92502e5f3f94d49ef5057dac08 |
|
BLAKE2b-256 | 6ea06f889b4485e83787244e7fbb21d1060b95d2b3bed564414610d596cb2032 |
Provenance
The following attestation bundles were made for cyclonedx_python_lib-8.4.0-py3-none-any.whl
:
Publisher:
release.yml
on CycloneDX/cyclonedx-python-lib
-
Statement type:
https://in-toto.io/Statement/v1
- Predicate type:
https://docs.pypi.org/attestations/publish/v1
- Subject name:
cyclonedx_python_lib-8.4.0-py3-none-any.whl
- Subject digest:
fd44efd601f651c8865acf0dfeacb0df19a2b50ec69ead0262096fd2f67197b9
- Sigstore transparency entry: 144698440
- Sigstore integration time:
- Predicate type: