pkg.soopen package index

brew / Rang 4223

cyclonedx-cli mit Homebrew, Nix, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für cyclonedx-cli in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install cyclonedx-cli

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#cyclonedx-cli

nixpkgs package indexes · pkgs/by-name/cy/cyclonedx-cli/package.nix · Quelle: api.github.com

Windows

Windows Package Managerverifiziert · 92%
winget install --id CycloneDX.CLI -e

Windows Package Manager source index · CycloneDX.CLI · Quelle: cdn.winget.microsoft.com

Überblick

Paketzusammenfassung

Tool for analysis and manipulation of CycloneDX SBOMs

Befehle und Aliase

  • cyclonedx

Verlauf

Projektgeschichte und Nutzung

CycloneDX CLI is the general-purpose command-line tool for analyzing, modifying, converting, diffing, merging, signing, verifying, and validating CycloneDX BOM files.

Projektgeschichte

The CycloneDX standard began as an OWASP security-focused Bill of Materials format in 2018, then expanded through versions 1.1 through 1.7 into pedigree, services, composition, VEX/VDR, AI transparency, cryptographic assets, attestation, and citation support. The cyclonedx-cli repository was created in October 2020 as a dedicated automation tool around those BOM documents.

Adoptionsgeschichte

CycloneDX's official site describes it as an international standard, with v1.6 ratified as ECMA-424 in June 2024, and its tool center lists hundreds of supporting tools. Within that ecosystem, cyclonedx-cli fills the package-manager-friendly role of a format workbench rather than a language-specific generator.

Wie es verwendet wird

The CLI is commonly used after an SBOM has already been produced: converting between XML, JSON, Protobuf, CSV, and SPDX JSON, validating against schema versions, merging component BOMs, diffing releases, and signing or verifying BOM artifacts in CI pipelines.

Warum Paket-Nerds sich dafür interessieren

For maintainers, cyclonedx-cli matters because it gives distributions and build systems a single executable for SBOM hygiene tasks that otherwise require language-specific libraries or custom scripts.

Zeitleiste

  • 2018: CycloneDX v1.0 introduced a general-purpose security-focused BOM standard.
  • 2020: cyclonedx-cli repository and early releases appeared.
  • 2024: CycloneDX v1.6 was ratified as ECMA-424, 1st Edition.
  • 2025: CycloneDX v1.7 added citation, patent, and expanded transparency support.

Related projects

  • The CLI sits beside language-specific generators such as cyclonedx-gomod and cyclonedx-python, and interoperates with SPDX through its conversion command.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für cyclonedx-cli wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
cyclonedxExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version0.33.1
Manager aktualisiert2026-07-23
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:cyclonedx-cli
Version0.33.1
PaketmanagerHomebrew
Homepagehttps://cyclonedx.org/
Repositoryhttps://github.com/CycloneDX/cyclonedx-cli
Zuletzt aktualisiert2026-07-23T20:40:19Z
Pulseupdated
Bottlenicht erfasst
Dienstkeiner deklariert

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

cyclonedx-cli

nix profile install nixpkgs#cyclonedx-cli
  • normalized package name match
  • Abgeglichen nach: Cyclonedx Cli
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/cy/cyclonedx-cli/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
winget95%

CycloneDX.CLI

winget install --id CycloneDX.CLI -e
  • normalized package name match
  • Abgeglichen nach: Cyclonedx Cli
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: CycloneDX.CLI from https://cdn.winget.microsoft.com/cache/source.msix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation