Skip to main content

Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Required by EO 14028 + NIS2 + CRA.

Project description

SBOM CycloneDX + SPDX Generator/Validator MCP

Buy Starter — £29/mo

Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.

Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.

PyPI License: MIT MEOK AI Labs

Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Required by EO 14028 + NIS2 + CRA.

Install

pip install sbom-cyclonedx-mcp

Tools

Tool Purpose
generate_sbom_cyclonedx Generate CycloneDX 1.6 SBOM from package manifests
generate_sbom_spdx Generate SPDX 2.3 SBOM
validate_sbom Validate SBOM against CycloneDX/SPDX schema + completeness
vex_attach Attach VEX (Vulnerability Exploitability eXchange) statements
regulation_map Map SBOM to EO 14028 / NIS2 / CRA / FDA requirements

Pairs with

  • meok-attestation-api — POST results to https://meok-attestation-api.vercel.app/sign for cryptographically signed compliance certs
  • meok-attestation-verify — public verification of any MEOK-signed cert
  • Other MEOK governance MCPs via SOV3 mcp_bridge_call

Pricing

  • Free: 10 calls/day. No API key required.
  • Pro £79/mo: unlimited + signed attestations. Subscribe
  • Enterprise £1,499/mo: white-label + on-premise + SLA. hello@meok.ai

Status

Scaffold v1.0.0 ships the MCP framework + 5 tool stubs. v1.1.0 will add real regulation data ingestion.

If your team needs this MCP fully-loaded faster, ping hello@meok.ai for sponsored development.

License

MIT © MEOK AI Labs

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sbom_cyclonedx_mcp-1.0.2.tar.gz (6.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sbom_cyclonedx_mcp-1.0.2-py3-none-any.whl (5.9 kB view details)

Uploaded Python 3

File details

Details for the file sbom_cyclonedx_mcp-1.0.2.tar.gz.

File metadata

  • Download URL: sbom_cyclonedx_mcp-1.0.2.tar.gz
  • Upload date:
  • Size: 6.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for sbom_cyclonedx_mcp-1.0.2.tar.gz
Algorithm Hash digest
SHA256 7cda338f193f8b617f506a926febb6c4e289116f5a5b771273c4f7f3ee834907
MD5 9ffc69301de86e70cbddc197a93efd8f
BLAKE2b-256 e283a831533cde03b0bf5698e9230f2a3fad610309cf95aa617f05579b2aa9da

See more details on using hashes here.

File details

Details for the file sbom_cyclonedx_mcp-1.0.2-py3-none-any.whl.

File metadata

File hashes

Hashes for sbom_cyclonedx_mcp-1.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 7a0a095eb9bc58e05b85a8233f3811ff9fc0ba46220f42f32cc3210001fde4f8
MD5 52f978ae571a99a40d7b43eed3179f39
BLAKE2b-256 ee6b97d35f55586bba91b4f5e89cea1fecbea814a9b2017ace8e93f8910490fe

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page