
CLI zum Erzeugen, Analysieren, Zusammenführen, Abgleichen, Validieren, Signieren und Konvertieren von CycloneDX-SBOMs in den Formaten JSON, XML, Protobuf, CSV und SPDX.
______ __ ____ _ __ ________ ____
/ ____/_ _______/ /___ ____ ___ / __ \ |/ / / ____/ / / _/
/ / / / / / ___/ / __ \/ __ \/ _ \/ / / / / / / / / / /
/ /___/ /_/ / /__/ / /_/ / / / / __/ /_/ / | / /___/ /____/ /
\____/\__, /\___/_/\____/_/ /_/\___/_____/_/|_| \____/_____/___/
/____/
Usage:
cyclonedx [command] [options]
Options:
--version Show version information
-?, -h, --help Show help and usage information
Commands:
add Add information to a BOM (currently supports files)
analyze Analyze a BOM file
convert Convert between different BOM formats
diff <from-file> <to-file> Generate a BOM diff
keygen Generates an RSA public/private key pair for BOM signing
merge Merge two or more BOMs
sign Sign a BOM or file
validate Validate a BOM
verify Verify signatures in a BOM
Das CycloneDX-CLI-Tool unterstützt derzeit Analyse, Modifikation, Vergleich, Zusammenführung, Formatkonvertierung, Signierung und Verifizierung von BOMs.
Die Konvertierung wird zwischen CycloneDX XML, JSON, Protobuf, CSV und SPDX JSON v2.3 unterstützt.
Binärdateien können von der Releases-Seite heruntergeladen werden.
Hinweis: Das CycloneDX-CLI-Tool ist für Automatisierungsanwendungsfälle konzipiert. Alle Befehle mit der Option --input-file unterstützen auch die Eingabe über stdin. Ebenso unterstützen alle Befehle mit der Option --output-file die Ausgabe über stdout. Allerdings müssen Sie die Eingabe-/Ausgabeformate angeben.
Zum Beispiel:
cat bom.json | cyclonedx-cli convert --input-format json --output-format xml > bom.xml
files
Add files to a BOM
Usage:
cyclonedx add files [options]
Options:
--input-file <input-file> Input BOM filename.
--no-input Use this option to indicate that there is no input BOM.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <autodetect|json|protobuf|xml> Specify output file format.
--base-path <base-path> Base path for directory to process (defaults to current working directory if omitted).
--include <include> Apache Ant style path and file patterns to specify what to include (defaults to all files, separate patterns with a space).
--exclude <exclude> Apache Ant style path and file patterns to specify what to exclude (defaults to none, separate patterns with a space).
Erzeugen einer Quellcode-BOM unter Ausschluss des Git-Repository-Verzeichnisses:
cyclonedx-cli add files --no-input --output-format json --exclude /.git/**
Hinzufügen von Build-Ausgabedateien aus dem Verzeichnis bin zu einer vorhandenen BOM:
cyclonedx-cli add files --input-file bom.json --output-format json --base-path bin
analyze
Analyze a BOM file
Usage:
cyclonedx analyze [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <json|text> Specify output format (defaults to text).
--multiple-component-versions Report components that have multiple versions in use.
Bericht über Komponenten, die mehrfach mit unterschiedlichen Versionen enthalten sind:
cyclonedx-cli analyze --input-file sbom.xml --multiple-component-versions
convert
Convert between different BOM formats
Usage:
cyclonedx convert [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify input file format.
--output-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify output file format.
--output-version <v1_0|v1_1|v1_2|v1_3|v1_4|v1_5|v1_6|v1_7> Specify output BOM specification version. (ignored for CSV and SPDX formats)
Konvertieren vom XML- ins JSON-Format:
cyclonedx-cli convert --input-file sbom.xml --output-file sbom.json
Konvertieren vom XML- ins JSON-Format und Weiterleiten der Ausgabe an weitere Tools:
cyclonedx-cli convert --input-file sbom.xml --output-format json | grep "somthing"
Das CSV-Format ist eine eingeschränkte Darstellung der Komponentenliste einer BOM.
Die Absicht besteht darin, Benutzern eine einfache Möglichkeit zu bieten, BOMs für einfache Anwendungsfälle zu erstellen und zu verarbeiten. Einschließlich einfacher Datenmigrations-Anwendungsfälle.
Die einzigen Pflichtfelder sind die Komponentenfelder name und version. Andere können leer gelassen oder die Spalten weggelassen werden.
Die Konvertierung zwischen SPDX- und CycloneDX-Formaten kann zum Verlust einiger Informationen führen. Die Konvertierungsfunktionalität wird von der Bibliothek CycloneDX.Spdx.Interop bereitgestellt, die Teil des CycloneDX-.NET-Bibliotheksprojekts ist.
Weitere Einzelheiten darüber, welche Informationen verloren gehen, finden Sie auf der Projektseite der CycloneDX-.NET-Bibliothek.
diff
Generate a BOM diff
Usage:
cyclonedx diff <from-file> <to-file> [options]
Arguments:
<from-file> From BOM filename.
<to-file> To BOM filename.
Options:
--from-format <autodetect|json|protobuf|xml> Specify from file format.
--to-format <autodetect|json|protobuf|xml> Specify to file format.
--output-format <json|text> Specify output format (defaults to text).
--component-versions Report component versions that have been added, removed or modified.
Bericht über Komponenten mit Versionsänderungen:
cyclonedx-cli diff sbom-from.xml sbom-to.xml --component-versions
keygen
Generates an RSA public/private key pair for BOM signing
Usage:
cyclonedx keygen [options]
Options:
--private-key-file <private-key-file> Filename for generated private key file (defaults to "private.key")
--public-key-file <public-key-file> Filename for generated public key file (defaults to "public.key")
merge
Merge two or more BOMs
Usage:
cyclonedx merge [options]