pkg.soopen package index

brew / rank 11921

Install bomctl with Homebrew, apk, zypper

Format-agnostic SBOM tooling for the stages between SBOM generation and analysis. Version 0.4.3 via Homebrew; verified 2026-07-26. Also installable with apk: sudo apk add bomctl.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install bomctl

local Homebrew formula metadata

overview

Package summary

Format-agnostic SBOM tooling for the stages between SBOM generation and analysis

Commands and aliases

  • bomctl

history

Project history and usage

bomctl is experimental, format-agnostic SBOM tooling intended to bridge the gap between SBOM generation and SBOM analysis tools.

Project history

The GitHub repository was created in January 2024. The README identifies bomctl as an OpenSSF Sandbox project under active development and says it builds on protobom for an SBOM-agnostic component graph.

Adoption history

The project documents installation through a Homebrew tap, container images on Docker Hub, and source builds, and the supplied package facts show availability through Homebrew, apk, and zypper.

How it is used

Users fetch, import, list, alias, merge, tag, export, and push SBOMs. bomctl stores SBOMs in a persistent cache and can fetch over HTTPS, OCI, Git, GitHub, and GitLab.

Why package nerds care

bomctl is interesting to package and supply-chain users because it treats SBOMs as package-like artifacts that can be cached, transformed, pushed, and moved between SPDX, CycloneDX, and related ecosystems.

Timeline

  • 2024: GitHub repository created.
  • 2024: v0.1.0-alpha appears in GitHub releases.
  • 2025: v0.4.3 appears in GitHub releases.

Related projects

  • protobom, OpenSSF, SPDX, CycloneDX, GUAC, Sigstore

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for bomctl. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.netrc

executables

Installed executables

CommandKindExposureNote
bomctlexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version0.4.3
manager updated2026-07-26
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:bomctl
Version0.4.3
Package managerHomebrew
Homepagehttps://github.com/bomctl/bomctl
Repositoryhttps://github.com/bomctl/bomctl
Last updated2026-07-26T10:56:34+02:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

apk95%

bomctl 0.1.9-r17

Format agnostic SBOM tooling

https://github.com/bomctl/bomctl

sudo apk add bomctl
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: bomctl
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Bomctl
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

bomctl-bash-completion 0.1.9-r17

Bash completions for bomctl

https://github.com/bomctl/bomctl

sudo apk add bomctl-bash-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: bomctl
  • normalized package name match
  • Matched by: Bomctl
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bomctl-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

bomctl-fish-completion 0.1.9-r17

Fish completions for bomctl

https://github.com/bomctl/bomctl

sudo apk add bomctl-fish-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: bomctl
  • normalized package name match
  • Matched by: Bomctl
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bomctl-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
apk95%

bomctl-zsh-completion 0.1.9-r17

Zsh completions for bomctl

https://github.com/bomctl/bomctl

sudo apk add bomctl-zsh-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: bomctl
  • normalized package name match
  • Matched by: Bomctl
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: bomctl-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz
zypper95%

bomctl 0.4.3-1.7

Format agnostic SBOM tooling

https://github.com/bomctl/bomctl

sudo zypper install bomctl
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: bomctl
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Bomctl
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst
zypper95%

bomctl-bash-completion 0.4.3-1.7

Bash Completion for bomctl

https://github.com/bomctl/bomctl

sudo zypper install bomctl-bash-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: bomctl
  • 2 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Bomctl
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: bomctl-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst
zypper95%

bomctl-fish-completion 0.4.3-1.7

Fish Completion for bomctl

https://github.com/bomctl/bomctl

sudo zypper install bomctl-fish-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: bomctl
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Bomctl
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: bomctl-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst
zypper95%

bomctl-zsh-completion 0.4.3-1.7

Zsh Completion for bomctl

https://github.com/bomctl/bomctl

sudo zypper install bomctl-zsh-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: bomctl
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Bomctl
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: bomctl-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation