# Install cyclonedx-cli with Homebrew, Nix, winget

Tool for analysis and manipulation of CycloneDX SBOMs. Version 0.33.1 via Homebrew; verified 2026-07-23. Also installable with nix: nix profile install nixpkgs#cyclonedx-cli.

## Install

```sh
sudo av install brew:cyclonedx-cli
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install cyclonedx-cli
```

  Evidence: local Homebrew formula metadata

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#cyclonedx-cli
```

  Evidence: nixpkgs package indexes: pkgs/by-name/cy/cyclonedx-cli/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

### Windows

- winget (92%):

```sh
winget install --id CycloneDX.CLI -e
```

  Evidence: Windows Package Manager source index: CycloneDX.CLI from https://cdn.winget.microsoft.com/cache/source.msix

## Package facts

- **Package key:** brew:cyclonedx-cli
- **Package manager:** Homebrew
- **Version:** 0.33.1
- **Source summary:** Tool for analysis and manipulation of CycloneDX SBOMs
- **Homepage:** <https://cyclonedx.org/>
- **Repository:** <https://github.com/CycloneDX/cyclonedx-cli>
- **Last updated:** 2026-07-23T20:40:19Z
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- cyclonedx (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 0.33.1
## Project history and usage

CycloneDX CLI is the general-purpose command-line tool for analyzing, modifying, converting, diffing, merging, signing, verifying, and validating CycloneDX BOM files.

### Project history

The CycloneDX standard began as an OWASP security-focused Bill of Materials format in 2018, then expanded through versions 1.1 through 1.7 into pedigree, services, composition, VEX/VDR, AI transparency, cryptographic assets, attestation, and citation support. The cyclonedx-cli repository was created in October 2020 as a dedicated automation tool around those BOM documents.

### Adoption history

CycloneDX's official site describes it as an international standard, with v1.6 ratified as ECMA-424 in June 2024, and its tool center lists hundreds of supporting tools. Within that ecosystem, cyclonedx-cli fills the package-manager-friendly role of a format workbench rather than a language-specific generator.

### How it is used

The CLI is commonly used after an SBOM has already been produced: converting between XML, JSON, Protobuf, CSV, and SPDX JSON, validating against schema versions, merging component BOMs, diffing releases, and signing or verifying BOM artifacts in CI pipelines.

### Why package nerds care

For maintainers, cyclonedx-cli matters because it gives distributions and build systems a single executable for SBOM hygiene tasks that otherwise require language-specific libraries or custom scripts.

### Timeline

- 2018: CycloneDX v1.0 introduced a general-purpose security-focused BOM standard.
- 2020: cyclonedx-cli repository and early releases appeared.
- 2024: CycloneDX v1.6 was ratified as ECMA-424, 1st Edition.
- 2025: CycloneDX v1.7 added citation, patent, and expanded transparency support.

### Related projects

- The CLI sits beside language-specific generators such as cyclonedx-gomod and cyclonedx-python, and interoperates with SPDX through its conversion command.

### Sources

- <https://cyclonedx.org/about/history/>
- <https://cyclonedx.org/docs/latest/>
- <https://cyclonedx.org/tool-center/>
- <https://github.com/CycloneDX/cyclonedx-cli/blob/main/README.md>
- <https://api.github.com/repos/CycloneDX/cyclonedx-cli>


## Security Notes

No matching local secret-handling manifest was found for cyclonedx-cli. Nucleus package metadata is still published here so future coverage has a stable package URL.


## Other Package-Manager Records

- Nix - cyclonedx-cli: normalized package name match | nixpkgs package indexes: pkgs/by-name/cy/cyclonedx-cli/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- winget - CycloneDX.CLI: normalized package name match | Windows Package Manager source index: CycloneDX.CLI from https://cdn.winget.microsoft.com/cache/source.msix


## Combined YAML source

View the package source record on GitHub. [combined/cyclonedx-cli.yml](https://github.com/mxcl/pkgdb/blob/main/combined/cyclonedx-cli.yml)


## Sources

- pkg.so package database
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
