CycloneDX Generator (cdxgen)

OWASP Foundation·CycloneDX.cdxgen

A polyglot tool and a library for generating various Bill of Materials in CycloneDX specification.

Generate Software Bill of Materials (SBOM) for most applications and container images with a single command. Generate Operations Bill of Materials (OBOM) for Linux and Windows hosts. Integrate with any CI/CD pipeline. Automatically submit the generated BOM to your dependency track server for analysis.

winget install --id CycloneDX.cdxgen --exact --source winget

Latest 13.1.0·September 4, 2026

Release Notes

cdxgen 13.1.0 Build introspection The headline change in this release is that cdxgen can now grade its own work. Run a scan with --introspect or --profile introspect and cdxgen reports how complete the resulting SBOM actually is, which parts of your build environment limited it, and what to fix. The verdict is not just a score. It is an evidence-driven repair loop: the report ranks the remediations that would actually raise fidelity, so you can work through them and re-scan until the tiers stop improving. This pairs with new JVM build tool detection and provisioning, so a project whose wrapper is broken or targets an unsupported JDK can still be resolved properly instead of quietly producing a shallow BOM. Claude Code plugin cdxgen now ships as a Claude Code plugin covering SBOM generation, container and host scans, CBOM, AI-BOM and MCP inventory, auditing, signing, validation, evidence enrichment, and Dependency-Track publishing. The skills encode cdxgen's safety rules, so an agent previews with a dry run before executing and does not install dependencies on your behalf. claude plugin marketplace add cdxgen/cdxgen claude plugin install cdxgen@cdxgen-plugins Deeper analysis for .NET, Go, and Rust The bundled analysis engines all moved forward in this release, and between them they change how much cdxgen can actually see. If you generate SaaSBOMs or rely on evidence and reachability, this is the part of 13.1.0 worth reading. .NET gains framework semantics. Dosai 4.0.0 introduces a new analysis schema built around provider-based framework detection. Instead of listing namespaces and methods, it now resolves routes, inventories services and AI usage, seeds taint sources, and maps trust zones, including MCP tooling. Route templates resolve to concrete URLs, so versioned segments like {version:apiVersion} come through as real endpoints rather than placeholders. Analysis is also considerably more robust: using-alias casts, duplicate symbols, deeply nested code, unreadable files, and the assembly memory blowup on large solutions are all fixed. Go understands your HTTP handlers. Golem now extracts handler signatures, so each route in a SaaSBOM carries its path and query parameters, request body type, and response type. This works across gin, chi, echo, and plain net/http, and it follows import aliases and renamed context parameters. Group-root registrations such as users.GET("", listUsers) resolve to their group prefix instead of being dropped. Go 1.27 is supported end to end, with encoding/json/v2 and post-quantum crypto modelled, and taint now carries field-qualified values across by-value aggregate copies and higher-order calls. Call graph construction no longer aborts a whole report when the underlying analysis panics: it degrades to a CHA fallback and records a diagnostic instead. Rust analysis is faster and much more accurate. Rusi 3.1.0 evaluates cfg attributes, resolves real modules and imports rather than guessing, types method receivers, recovers from macros, and analyses dependencies. The call graph is leaner and roughly ten times faster to build. The toolchain moves to Rust 1.98 with syn 3. Alongside these, Trivy and trustinspector pick up Go 1.27, and pnpm 11.25.0 and Deno 2.9.6 are in for the runtime paths. Python accuracy Framework signals are now derived from PyPI classifiers, and the frameworks list has grown. Lock file parsing emits the parent dependency edge and repairs missing root edges, Poetry dependency keys are normalised, and first-party modules are no longer misattributed to distributions. An unparseable workspace pyproject.toml no longer takes the whole scan down. Dependency-Track BOM submission now uses a multipart form POST, and project tags are sent as a comma separated list. If you were seeing tags land as a single value, this fixes it. Other fixes worth knowing Distro qualifiers are aligned with purl namespaces, and Azure Linux and CBL-Mariner are canonicalised to azure-linux. The cbom command now rejects -t os rather than attempting source crypto analysis against an OS inventory, which was slow and meaningless. Several Windows path and process handling bugs are resolved. Audit rules stay evaluable when a property is absent. Full Changelog: v13.0.1...v13.1.0

Installer type: portable

x64—F5AB12F5A3B998BA1C90AFDC97CAA65BFCABEF9CB72DCA869226FAEEB2B3B1BD

Details

Homepage
https://github.com/CycloneDX/cdxgen
License
Apache-2.0
Publisher
OWASP Foundation
Support
https://github.com/CycloneDX/cdxgen/issues
Moniker
cdxgen

Tags

bomcbomcontainerscyclonedxdockerociowasppackage-urlpurlsaasbomsbomscasoftware-bill-of-materialssupply-chain

Older versions (52)

13.0.1
x64—D9767898D1076438CAB497E2C74C68F2CA76751DB6A3F69627CBBC87E189F458
13.0.0
x64—8113E4617E40B669548AB396E605E02A032983DB42375A424926369481F02540
12.8.3
x64—F3E014A9EC35E864E6FC4A0547A00068C8F752F2B952E69C1B1F9A4E995A8763
12.8.2
x64—318CDE28194B6977E291E97C2B8600A91FC1185F41ED6CC658FB9846A7FCFC8B
12.8.1
x64—AC9025A33AFFDF5651B7AAA5947391878EC4C07563278FCB8C5BEDD77CC84788
12.8.0
x64—16943508AA3EED1F14A4456CB3491F1783244A63B036E40D596FE424D420D076
12.7.1
x64—B2751566100AE5CE85975961A07A1EF8F5B4D3BC0F27A3165967488EFA94DF6C
12.7.0
x64—C92A793C5E3177CAA3297DF88317529D9D225113CF0B4C7BB144438B0DB257D1
12.6.0
x64—F3E574377AE6A850DD82EAFA901E7BFFDDFC4B503BB3710E608E6E9544B141EE
12.5.1
x64—7B409D7199C3795D6378A33756FC8B2FB8A26153C2E010D67961D98F989EACE3
12.5.0
x64—C5C8C345A7056AE769823A8E45BC4458DCB5E6155FE451A55B764D03A399C4C5
12.4.4
x64—444E7714C004049DC5ACD9A74A13298BAB714E52330700DDFA1E6326B09711E7
12.4.3
x64—95CC002E54428770587C3399443B1EDA5A0DD8B6FAE95ACA02F0A449A9E50BA3
12.4.2
x64—0B1A4A7D07BD1BFCEB57D36715392F11A5921058FE3091B4C9A2EE7C540490B9
12.4.1
x64—7F7898E103231D44CE6CE0EA42C0CFC75E3244DF7A81312E068D03828AD8EDED
12.4.0
x64—D89F75FE4ED72D3E34CE07A0CF1D8C8988BBE3EC311F5C94D721CD4B4716C2CC
12.3.3
x64—7BB2AFE76CD18086BB31B0BF7B4EE898E717A46A33E5C4C39496492A0785FF62
12.3.2
x64—181E7D3AA22FE588C90EDBB53EA9A2DDDE6C746BE8F230F61BF248707A48B57A
12.3.1
x64—2B98C8F33268FDE61ED849FF0616F5BAE5720D889778A852F94439B9000F3495
12.3.0
x64—5B963F1C12F752372A360AACC279D4CEF566BBAC1261775286372600F13FDCD4
12.2.1
x64—470E0E806E7B638AE8F0EC5839D39399C79175574565B6AB5594EB26E14EA527
12.2.0
x64—00FECB55B50A3AD1E8E42E5BB011C7086CA80875D1A31405625AC8961EF73D15
12.1.5
x64—19D9EBD3F5ED1390CC33C1AC503AE5504BB201959F7A09A3158AC87F4C5044BD
12.1.4
x64—607AFFB6EB91692133409E4654E0FC0896BE99407FFDF2A147BA9450739C8ADC
12.1.3
x64—BA5A684C7F6BA93AC8174B9A3ACD85D1A5D1717E09CE4F06CEF1EA174E942310
12.1.2
x64—B14DAB570906B46B7DD63247A9A85FFCC7B8E5792824FA75A41DF2DD36596B3F
12.1.1
x64—0F6B20ED599FAB7691C9B1B5198C6B55308CD60849640E5802E4F33B3902CCB9
12.1.0
x64—B8410E379374224C5424EC95399BC047B84DABDB202A420BBD31DCDA630C979C
12.0.0
x64—9660B2AEC4ED897C3E89EFA33D4F648D6D83E3987C8FDA791DC77DF2F97B8C7C
11.11.0
x64—029E94F13C99A52169B0EFF7585F1181A7B6A4C654FDAB7ED02105677123D1EF
11.10.0
x64—7040F626082A19F687EF9E39CA12B22FD19C8322588F00B84E3C5257E6CE3612
11.9.0
x64—63CE182C19ABEB7C949181C72599E798014784A8D8D616A2BC8659832800EEDF
11.8.0
x64—CA5BBD6D04279970AF3E04566E8888ED250BE9A7EDC6ADC52BDE9D20EE4479CB
11.7.0
x64—730AFB5DA16150E15D1046811003713AA2CF570175140FCFAEF633E004A90380
11.6.0
x64—C186406861E40E11FE2F8371EF8830E66017F3ADD117AEDEE26E77C85E37650D
11.5.0
x64—CCEF5A440AA535EC3B56229B4E2EED5676EDC02B4C366017D669BFF51CD12532
11.4.3
x64—C7B95E62D4653AE7EB7AE1A3FB765649A4AF6DA34B2B2B391D91740A3D29FA33
11.4.2
x64—AD5530E5E4365D838F4D28F6735C1AFED431F61393CBC6DB3F278CBC5CA3F063
11.4.1
x64—2005FA5A299C77511C534B1DF3CEB7D342FDAEB3D3AA1761B4775F8D184EFA96
11.4.0
x64—EA554DDE1DAB225C79654F002FA4C63B6D6FCEAA0A6D5EBD734A080547D012A3
11.3.2
x64—C568D9B1963ABA04F25F1CF05E0EA7CE223F6FF899C3BF0ABF79468466887154
11.3.1
x64—8181662C4140F756AE3FC318642A9779A542FE655391C99167193DF17335C121
11.3.0
x64—DE30E1DE54DFF84A2CA6921FE2E794BCAA52238B70874CDBC6D67D69BB109291
11.2.7
x64—B06642E8C15479F600D9DA055659657FCC69C50C3482C2792F8143A1AA0CECE7
11.2.6
x64—DBE9E84FF27902710CB1C46566F7A7DFCB83528E8D1FF3FE2265FF878C9E240A
11.2.5
x64—A8303AA9FEF26C43A07D70C7BD075D7F3AA53E95A9B4275523B58507D5416FD2
11.2.4
x64—685D1281854315C951A4410A3F9DB3A568AAF4B29E6395186E167363E7343201
11.2.3
x64—43DB4CB53F45B3CF32688B2D3B5E8121FC361A01BE9215BC7AE73F0814E7C58F
11.2.2
x64—F47335133C1E9080FEDA4044DFFD295338A5FF5B1CCD1AC31DAC92BA40A7C43F
11.2.1
x64—18C0C17955C5AF8BF1D83B248B24F1FB17DD007BFC35607B60DDDEAFB26388BA
11.2.0
x64—AB6E6543164ADE7127DD5FAD82B243F178AB504489CF2F16CF15B35C1D242B32
11.1.10
x64—E75692EB7B1ED548AE526530464A3E2B062434F3337E7D3891A331A19715FE43