Skip to main content

📓 Software Bill-of-Materials for vcpkg manifests.

Python Version PyPI PyPI - Wheel PyPI - Status GitHub Release Date PyPI - Downloads

GitHub repo size PyPI - License Code style: black Black Format Discord


A python command line tool to extract a combined software bill of materials and license info from a vcpkg manifest.

Installation

:snake: PyPi

Open a command line and run:

pip install vcpkg-sbom

:octocat: Local

Downlaod the repo:

git clone https://github.com/moverseai/vcpkg-sbom vcpkg-sbom
cd vcpkg-sbom

From the repo's root path run:

pip install .

For an editable install run:

pip install -e .

:keyboard: Usage

vcpkg-sbom PATH/TO/PROJECT/vcpkg_installed
ID Package
0 package name #1
1 package name #2
2 package name #3
... package name #N

Merging spdx: ━━━━━━━━━━━━━━━━━━ 100% 0:00:00

Extracting & merging copyrights ...

Merging copyrights: ━━━━━━━━━━━━━━━━━━ 0% -:--:--

[!NOTE]
The output file is a SPDX-2.3 SPDXRef-DOCUMENT that merges all available *.spdx.json files from the manifest's installed packages.

[!TIP]
The default triplet is x64-windows and is appended to the cmd line given path before searching for all installed packages.

[!IMPORTANT]
The output files (*.spdx.json, and optionally, *_license_info.json and *_EULA.txt) are written to the current working directory from where the command was executed.


🔧 Command Line API

$ vcpkg-sbom --help
usage: A software bill of materials extracter and merger for `vcpkg` manifest projects.

positional arguments:
  vcpkg_root            Path to the `vcpkg_installed` folder of your manifest project.

options:
  -h, --help            show this help message and exit
  -t TRIPLET, --triplet TRIPLET
                        The `vcpkg` triplet to use.
  -p PROJECT, --project PROJECT
                        The project's name that will be used for the merged output files.
  -n NAMESPACE, --namespace NAMESPACE
                        The software's namespace to use for the `spdx` file.
  -o ORGANIZATION, --organization ORGANIZATION
                        The organization or company name to use for the `spdx` file.
  -e EMAIL, --email EMAIL
                        The email to use for the `spdx` file.
  -c, --copyright       Additionally extract and merge all copyright files in a `*.txt` file.
  -l, --license         Additionally extract and merge all license types in a `*.json` file.

[!IMPORTANT] Default values:

  • triplet: x64-windows
  • project: project
  • namespace: https://spdx.org/spdxdocs/
  • organization: org
  • email: info@org.com
  • copyright: flag to enable copyright file merging
  • license: flag to enable license info merging

[!TIP]
Info on how to choose a proper namespace can be found here

Acknowledgements / Material

Disclaimer / Limitations

[!WARNING] As indicated at the vcpkg docs: The licensing information provided for each package in the vcpkg registry represents Microsoft's best understanding of the licensing requirements. However, this information may not be definitive. Users are advised to verify the exact licensing requirements for each package they intend to use, as it is ultimately their responsibility to ensure compliance with the applicable licenses.

While vcpkg offers a lot of information about licensing, this information should be scrutinized. Any tool that builds on top of this information provided by vcpkg is reliant on the legibility of the provided data, and should thus, be also scrutinized for correctness.

Metadata

Release files for vcpkg-sbom 0.0.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vcpkg-sbom 0.0.6
File Size Uploaded
vcpkg_sbom-0.0.6.tar.gz 9.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vcpkg-sbom 0.0.6
File Interpreter ABI Platform
vcpkg_sbom-0.0.6-py3-none-any.whl Python 3 none any Details

Total release size: 17.7 kB

Release files / vcpkg_sbom-0.0.6.tar.gz

Download URL vcpkg_sbom-0.0.6.tar.gz
Size 9.9 kB
Tags Source
SHA-256 checksum
How to use checksums
39de054d514196126a7735a016c9231d700b92763bd1fe66e0b82f86bd8d5db7
BLAKE2b-256 checksum
How to use checksums
810637858b7413c9a3fda9daf78584bb25664a6e2a61275782c6308277e7b596
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.1 CPython/3.12.7

Release files / vcpkg_sbom-0.0.6-py3-none-any.whl

Download URL vcpkg_sbom-0.0.6-py3-none-any.whl
Size 7.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
26f4bc67292aec68bcf2950fc345322abc67ba99f761a80b8bf8c221610de4dd
BLAKE2b-256 checksum
How to use checksums
dd6913678287877c331de61512be2658a92ad95194681fc65ec717036c16ad41
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.1 CPython/3.12.7

Release history Release notifications | RSS feed

This release

0.0.6 This release

2 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page