
واجهة سطر أوامر (CLI) لتوليد وتحليل ودمج ومقارنة والتحقق من وتوقيع وتحويل ملفات SBOM بصيغة CycloneDX عبر تنسيقات JSON وXML وProtobuf وCSV وSPDX.
______ __ ____ _ __ ________ ____
/ ____/_ _______/ /___ ____ ___ / __ \ |/ / / ____/ / / _/
/ / / / / / ___/ / __ \/ __ \/ _ \/ / / / / / / / / / /
/ /___/ /_/ / /__/ / /_/ / / / / __/ /_/ / | / /___/ /____/ /
\____/\__, /\___/_/\____/_/ /_/\___/_____/_/|_| \____/_____/___/
/____/
Usage:
cyclonedx [command] [options]
Options:
--version Show version information
-?, -h, --help Show help and usage information
Commands:
add Add information to a BOM (currently supports files)
analyze Analyze a BOM file
convert Convert between different BOM formats
diff <from-file> <to-file> Generate a BOM diff
keygen Generates an RSA public/private key pair for BOM signing
merge Merge two or more BOMs
sign Sign a BOM or file
validate Validate a BOM
verify Verify signatures in a BOM
تدعم أداة سطر الأوامر CycloneDX CLI حالياً تحليل ملفات BOM وتعديلها وحساب الفروقات بينها ودمجها وتحويل التنسيقات وتوقيعها والتحقق منها.
يُدعم التحويل بين تنسيقات CycloneDX XML وJSON وProtobuf وCSV وSPDX JSON v2.3.
يمكن تنزيل الملفات التنفيذية من صفحة الإصدارات.
ملاحظة: أُنشئت أداة CycloneDX CLI لحالات الاستخدام المؤتمتة. أي أمر يحتوي على الخيار --input-file يدعم أيضاً إدخال البيانات من stdin. وبالمثل، فإن أي أمر يحتوي على الخيار --output-file يدعم إخراج البيانات إلى stdout. ومع ذلك، ستحتاج إلى تحديد تنسيقات الإدخال والإخراج.
على سبيل المثال:
cat bom.json | cyclonedx-cli convert --input-format json --output-format xml > bom.xml
files
Add files to a BOM
Usage:
cyclonedx add files [options]
Options:
--input-file <input-file> Input BOM filename.
--no-input Use this option to indicate that there is no input BOM.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <autodetect|json|protobuf|xml> Specify output file format.
--base-path <base-path> Base path for directory to process (defaults to current working directory if omitted).
--include <include> Apache Ant style path and file patterns to specify what to include (defaults to all files, separate patterns with a space).
--exclude <exclude> Apache Ant style path and file patterns to specify what to exclude (defaults to none, separate patterns with a space).
إنشاء BOM لكود المصدر مع استبعاد دليل مستودع Git:
cyclonedx-cli add files --no-input --output-format json --exclude /.git/**
إضافة ملفات مخرجات البناء من دليل bin إلى BOM موجود:
cyclonedx-cli add files --input-file bom.json --output-format json --base-path bin
analyze
Analyze a BOM file
Usage:
cyclonedx analyze [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <json|text> Specify output format (defaults to text).
--multiple-component-versions Report components that have multiple versions in use.
الإبلاغ عن المكونات المضمّنة أكثر من مرة بإصدارات مختلفة:
cyclonedx-cli analyze --input-file sbom.xml --multiple-component-versions
convert
Convert between different BOM formats
Usage:
cyclonedx convert [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify input file format.
--output-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify output file format.
--output-version <v1_0|v1_1|v1_2|v1_3|v1_4|v1_5|v1_6|v1_7> Specify output BOM specification version. (ignored for CSV and SPDX formats)
التحويل من تنسيق XML إلى تنسيق JSON:
cyclonedx-cli convert --input-file sbom.xml --output-file sbom.json
التحويل من تنسيق XML إلى تنسيق JSON وتوجيه المخرجات إلى أدوات إضافية:
cyclonedx-cli convert --input-file sbom.xml --output-format json | grep "somthing"
تنسيق CSV هو تمثيل محدود لقائمة المكونات في BOM.
الهدف هو توفير طريقة بسيطة للمستخدمين لإنتاج واستهلاك ملفات BOM لحالات الاستخدام البسيطة، بما في ذلك حالات ترحيل البيانات البسيطة.
الحقلان الوحيدان المطلوبان هما حقلا المكوّن name وversion. ويمكن ترك الحقول الأخرى فارغة أو حذف الأعمدة.
يمكن أن يؤدي التحويل بين تنسيقي SPDX وCycloneDX إلى فقدان بعض المعلومات. وظيفة التحويل مُقدَّمة من مكتبة CycloneDX.Spdx.Interop، وهي جزء من مشروع مكتبة CycloneDX .NET.
لمزيد من التفاصيل حول المعلومات المفقودة، راجع صفحة مشروع مكتبة CycloneDX .NET.
diff
Generate a BOM diff
Usage:
cyclonedx diff <from-file> <to-file> [options]
Arguments:
<from-file> From BOM filename.
<to-file> To BOM filename.
Options:
--from-format <autodetect|json|protobuf|xml> Specify from file format.
--to-format <autodetect|json|protobuf|xml> Specify to file format.
--output-format <json|text> Specify output format (defaults to text).
--component-versions Report component versions that have been added, removed or modified.
الإبلاغ عن المكونات التي تغيّرت إصداراتها:
cyclonedx-cli diff sbom-from.xml sbom-to.xml --component-versions
keygen
Generates an RSA public/private key pair for BOM signing
Usage:
cyclonedx keygen [options]
Options:
--private-key-file <private-key-file> Filename for generated private key file (defaults to "private.key")
--public-key-file <public-key-file> Filename for generated public key file (defaults to "public.key")
merge
Merge two or more BOMs
Usage:
cyclonedx merge [options]