# Install bomctl with Homebrew, apk, zypper

Format-agnostic SBOM tooling for the stages between SBOM generation and analysis. Version 0.4.3 via Homebrew; verified 2026-07-26. Also installable with apk: sudo apk add bomctl.

## Install

```sh
sudo av install brew:bomctl
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install bomctl
```

  Evidence: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add bomctl
```

  Evidence: Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz

- zypper (92%):

```sh
sudo zypper install bomctl
```

  Evidence: openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

## Package facts

- **Package key:** brew:bomctl
- **Package manager:** Homebrew
- **Version:** 0.4.3
- **Source summary:** Format-agnostic SBOM tooling for the stages between SBOM generation and analysis
- **Homepage:** <https://github.com/bomctl/bomctl>
- **Repository:** <https://github.com/bomctl/bomctl>
- **Last updated:** 2026-07-26T10:56:34+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- bomctl (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 0.4.3
## Project history and usage

bomctl is experimental, format-agnostic SBOM tooling intended to bridge the gap between SBOM generation and SBOM analysis tools.

### Project history

The GitHub repository was created in January 2024. The README identifies bomctl as an OpenSSF Sandbox project under active development and says it builds on protobom for an SBOM-agnostic component graph.

### Adoption history

The project documents installation through a Homebrew tap, container images on Docker Hub, and source builds, and the supplied package facts show availability through Homebrew, apk, and zypper.

### How it is used

Users fetch, import, list, alias, merge, tag, export, and push SBOMs. bomctl stores SBOMs in a persistent cache and can fetch over HTTPS, OCI, Git, GitHub, and GitLab.

### Why package nerds care

bomctl is interesting to package and supply-chain users because it treats SBOMs as package-like artifacts that can be cached, transformed, pushed, and moved between SPDX, CycloneDX, and related ecosystems.

### Timeline

- 2024: GitHub repository created.
- 2024: v0.1.0-alpha appears in GitHub releases.
- 2025: v0.4.3 appears in GitHub releases.

### Related projects

- protobom, OpenSSF, SPDX, CycloneDX, GUAC, Sigstore

### Sources

- <https://api.github.com/repos/bomctl/bomctl>
- <https://github.com/bomctl/bomctl#readme>
- <https://github.com/bomctl/bomctl/tree/main/docs/architecture>


## Security Notes

No matching local secret-handling manifest was found for bomctl. Nucleus package metadata is still published here so future coverage has a stable package URL.



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: ~/.netrc
## Other Package-Manager Records

- apk - bomctl - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Format agnostic SBOM tooling | https://github.com/bomctl/bomctl
- apk - bomctl-bash-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Bash completions for bomctl | https://github.com/bomctl/bomctl
- apk - bomctl-fish-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Fish completions for bomctl | https://github.com/bomctl/bomctl
- apk - bomctl-zsh-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Zsh completions for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Format agnostic SBOM tooling | https://github.com/bomctl/bomctl
- zypper - bomctl-bash-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Bash Completion for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl-fish-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Fish Completion for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl-zsh-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Zsh Completion for bomctl | https://github.com/bomctl/bomctl


## Combined YAML source

View the package source record on GitHub. [combined/bomctl.yml](https://github.com/mxcl/pkgdb/blob/main/combined/bomctl.yml)


## Sources

- pkg.so package database
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
