Skip to content
@CycloneDX

CycloneDX BOM Standard

CycloneDX is a modern standard for the software supply chain. SBOM, SaaSBOM, CBOM, OBOM, VEX, and more. CycloneDX is a OWASP project ratified as ECMA-424

Welcome to the CycloneDX Community

CycloneDX logo

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. The specification supports:

  • Software Bill of Materials (SBOM)
  • Software-as-a-Service Bill of Materials (SaaSBOM)
  • Hardware Bill of Materials (HBOM)
  • Machine Learning Bill of Materials (ML-BOM)
  • Cryptography Bill of Materials (CBOM)
  • Manufacturing Bill of Materials (MBOM)
  • Operations Bill of Materials (OBOM)
  • Vulnerability Disclosure Reports (VDR)
  • Vulnerability Exploitability eXchange (VEX)
  • CycloneDX Attestations (CDXA)

The CycloneDX project provides standards in XML, JSON, and Protocol Buffers, as well as a large collection of official and community supported tools that create or interoperate with the standard.

The project's website has many documented use cases and examples that provide a springboard to SBOM adoption.

The project operates as a meritocracy whose guiding principles reinforce its risk-based approach to standards development. The project encourages community participation in the development of the standard and supporting tools.

Background

Modern software is assembled using third-party and open source components. They are glued together in complex and unique ways and integrated with original code to achieve the desired functionality. An accurate inventory of all components enables organizations to identify risk, allows for greater transparency, and enables rapid impact analysis.

CycloneDX was created for this purpose.

Strategic direction and maintenance of the specification is managed by the CycloneDX Core Working Group, is backed by the OWASP Foundation, and is supported by the global information security community.

Pinned Loading

  1. specification Public

    OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, an…

    XSLT 394 67

  2. cyclonedx-python Public

    CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments

    Python 276 73

  3. cyclonedx-maven-plugin Public

    Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects

    Java 320 88

  4. cyclonedx-cli Public

    CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.

    C# 349 63

  5. bom-examples Public

    A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)

    193 70

  6. cyclonedx-node-module Public

    creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects

    127 38

Repositories

Showing 10 of 60 repositories
  • transparency-exchange-api Public

    A standard API specification for exchanging supply chain artifacts and intelligence

    Shell 77 Apache-2.0 15 39 10 Updated Apr 17, 2025
  • specification Public

    OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX

    XSLT 394 Apache-2.0 67 125 (5 issues need help) 16 Updated Apr 17, 2025
  • cyclonedx-php-library Public

    PHP Implementation of OWASP CycloneDX Bill of Materials (BOM)

    PHP 9 Apache-2.0 0 13 (4 issues need help) 3 Updated Apr 17, 2025
  • cdxgen Public

    Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server. GPT: https://chatgpt.com/g/g-673bfeb4037481919be8a2cd1bf868d2-cdxgen

    JavaScript 672 Apache-2.0 177 364 (29 issues need help) 12 Updated Apr 17, 2025
  • sbom-utility Public

    Utility that provides an API platform for validating, querying and managing BOM data

    Go 106 Apache-2.0 16 27 (16 issues need help) 1 Updated Apr 16, 2025
  • cyclonedx-gomod Public

    Creates CycloneDX Software Bill of Materials (SBOM) from Go modules

    Go 151 Apache-2.0 26 26 (1 issue needs help) 5 Updated Apr 16, 2025
  • cyclonedx-webpack-plugin Public

    Generate CycloneDX Software Bill of Materials (SBOM) from webpack bundles at compile time.

    JavaScript 26 Apache-2.0 9 9 (7 issues need help) 5 Updated Apr 16, 2025
  • cyclonedx-buildroot Public

    Create CycloneDX Software Bill of Materials (SBOM) for Buildroot projects

    Python 11 Apache-2.0 6 7 0 Updated Apr 15, 2025
  • official-3rd-party-standards Public

    A collection of machine-readable third-party standards and requirements in CycloneDX format

    Python 6 Apache-2.0 2 1 3 Updated Apr 15, 2025
  • cyclonedx-php-composer Public

    Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects

    PHP 64 Apache-2.0 7 14 (8 issues need help) 0 Updated Apr 15, 2025