# bomctl を Homebrew, apk, zypper でインストール

bomctl のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install brew:bomctl
```

追加のインストールコマンド:

### macOS

- Homebrew (100%):

```sh
brew install bomctl
```

  証拠: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add bomctl
```

  証拠: Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz

- zypper (92%):

```sh
sudo zypper install bomctl
```

  証拠: openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

## パッケージ情報

- **パッケージキー:** brew:bomctl
- **パッケージマネージャ:** Homebrew
- **バージョン:** 0.4.3
- **ソース概要:** Format-agnostic SBOM tooling for the stages between SBOM generation and analysis
- **ホームページ:** <https://github.com/bomctl/bomctl>
- **リポジトリ:** <https://github.com/bomctl/bomctl>
- **最終更新:** 2026-07-26T10:56:34+02:00
- **生成日時:** 2026-08-03T19:37:03+00:00

## 実行可能ファイル

- bomctl (エイリアス)

## インストール挙動

- Bottle: 利用不可

## バージョンと鮮度

- ページ生成日: 2026-08-03
- マネージャ版: 0.4.3
## プロジェクトの歴史と使われ方

bomctl is experimental, format-agnostic SBOM tooling intended to bridge the gap between SBOM generation and SBOM analysis tools.

### プロジェクトの歴史

The GitHub repository was created in January 2024. The README identifies bomctl as an OpenSSF Sandbox project under active development and says it builds on protobom for an SBOM-agnostic component graph.

### 採用の歴史

The project documents installation through a Homebrew tap, container images on Docker Hub, and source builds, and the supplied package facts show availability through Homebrew, apk, and zypper.

### 使われ方

Users fetch, import, list, alias, merge, tag, export, and push SBOMs. bomctl stores SBOMs in a persistent cache and can fetch over HTTPS, OCI, Git, GitHub, and GitLab.

### パッケージ好きにとっての重要性

bomctl is interesting to package and supply-chain users because it treats SBOMs as package-like artifacts that can be cached, transformed, pushed, and moved between SPDX, CycloneDX, and related ecosystems.

### タイムライン

- 2024: GitHub repository created.
- 2024: v0.1.0-alpha appears in GitHub releases.
- 2025: v0.4.3 appears in GitHub releases.

### Related projects

- protobom, OpenSSF, SPDX, CycloneDX, GUAC, Sigstore

### ソース

- <https://api.github.com/repos/bomctl/bomctl>
- <https://github.com/bomctl/bomctl#readme>
- <https://github.com/bomctl/bomctl/tree/main/docs/architecture>


## セキュリティノート

bomctl に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: ~/.netrc
## 他のパッケージマネージャ記録

- apk - bomctl - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Format agnostic SBOM tooling | https://github.com/bomctl/bomctl
- apk - bomctl-bash-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Bash completions for bomctl | https://github.com/bomctl/bomctl
- apk - bomctl-fish-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Fish completions for bomctl | https://github.com/bomctl/bomctl
- apk - bomctl-zsh-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Zsh completions for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Format agnostic SBOM tooling | https://github.com/bomctl/bomctl
- zypper - bomctl-bash-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Bash Completion for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl-fish-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Fish Completion for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl-zsh-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Zsh Completion for bomctl | https://github.com/bomctl/bomctl


## Combined YAML source

View the package source record on GitHub. [combined/bomctl.yml](https://github.com/mxcl/pkgdb/blob/main/combined/bomctl.yml)


## ソース

- pkg.so package database
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
