# 使用 Homebrew, apk, zypper 安装 bomctl

查看 bomctl 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:bomctl
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install bomctl
```

  证据: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add bomctl
```

  证据: Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz

- zypper (92%):

```sh
sudo zypper install bomctl
```

  证据: openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

## 软件包事实

- **软件包键:** brew:bomctl
- **软件包管理器:** Homebrew
- **版本:** 0.4.3
- **来源摘要:** Format-agnostic SBOM tooling for the stages between SBOM generation and analysis
- **主页:** <https://github.com/bomctl/bomctl>
- **仓库:** <https://github.com/bomctl/bomctl>
- **最后更新:** 2026-07-26T10:56:34+02:00
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- bomctl (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 0.4.3
## 项目历史与用法

bomctl is experimental, format-agnostic SBOM tooling intended to bridge the gap between SBOM generation and SBOM analysis tools.

### 项目历史

The GitHub repository was created in January 2024. The README identifies bomctl as an OpenSSF Sandbox project under active development and says it builds on protobom for an SBOM-agnostic component graph.

### 采用历史

The project documents installation through a Homebrew tap, container images on Docker Hub, and source builds, and the supplied package facts show availability through Homebrew, apk, and zypper.

### 使用方式

Users fetch, import, list, alias, merge, tag, export, and push SBOMs. bomctl stores SBOMs in a persistent cache and can fetch over HTTPS, OCI, Git, GitHub, and GitLab.

### 为什么软件包爱好者会关心

bomctl is interesting to package and supply-chain users because it treats SBOMs as package-like artifacts that can be cached, transformed, pushed, and moved between SPDX, CycloneDX, and related ecosystems.

### 时间线

- 2024: GitHub repository created.
- 2024: v0.1.0-alpha appears in GitHub releases.
- 2025: v0.4.3 appears in GitHub releases.

### Related projects

- protobom, OpenSSF, SPDX, CycloneDX, GUAC, Sigstore

### 来源

- <https://api.github.com/repos/bomctl/bomctl>
- <https://github.com/bomctl/bomctl#readme>
- <https://github.com/bomctl/bomctl/tree/main/docs/architecture>


## 安全说明

没有找到 bomctl 的匹配本地密钥处理 manifest。Nucleus 软件包元数据仍在此发布，以便未来覆盖拥有稳定的软件包 URL。



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: ~/.netrc
## 其他软件包管理器记录

- apk - bomctl - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Format agnostic SBOM tooling | https://github.com/bomctl/bomctl
- apk - bomctl-bash-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Bash completions for bomctl | https://github.com/bomctl/bomctl
- apk - bomctl-fish-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Fish completions for bomctl | https://github.com/bomctl/bomctl
- apk - bomctl-zsh-completion - 0.1.9-r17: normalized package name match | Alpine Linux edge package indexes: bomctl-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Zsh completions for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Format agnostic SBOM tooling | https://github.com/bomctl/bomctl
- zypper - bomctl-bash-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Bash Completion for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl-fish-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Fish Completion for bomctl | https://github.com/bomctl/bomctl
- zypper - bomctl-zsh-completion - 0.4.3-1.7: normalized package name match | openSUSE Tumbleweed package metadata: bomctl-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Zsh Completion for bomctl | https://github.com/bomctl/bomctl


## Combined YAML source

View the package source record on GitHub. [combined/bomctl.yml](https://github.com/mxcl/pkgdb/blob/main/combined/bomctl.yml)


## 来源

- pkg.so package database
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
