
CLI per generare, analizzare, unire, confrontare, validare, firmare e convertire SBOM CycloneDX nei formati JSON, XML, Protobuf, CSV e SPDX.
______ __ ____ _ __ ________ ____
/ ____/_ _______/ /___ ____ ___ / __ \ |/ / / ____/ / / _/
/ / / / / / ___/ / __ \/ __ \/ _ \/ / / / / / / / / / /
/ /___/ /_/ / /__/ / /_/ / / / / __/ /_/ / | / /___/ /____/ /
\____/\__, /\___/_/\____/_/ /_/\___/_____/_/|_| \____/_____/___/
/____/
Usage:
cyclonedx [command] [options]
Options:
--version Show version information
-?, -h, --help Show help and usage information
Commands:
add Add information to a BOM (currently supports files)
analyze Analyze a BOM file
convert Convert between different BOM formats
diff <from-file> <to-file> Generate a BOM diff
keygen Generates an RSA public/private key pair for BOM signing
merge Merge two or more BOMs
sign Sign a BOM or file
validate Validate a BOM
verify Verify signatures in a BOM
Lo strumento CLI CycloneDX supporta attualmente analisi, modifica, differenza (diff), unione (merge), conversione di formato, firma e verifica dei BOM.
La conversione è supportata tra CycloneDX XML, JSON, Protobuf, CSV e SPDX JSON v2.3.
I binari possono essere scaricati dalla pagina delle release.
Nota: lo strumento CLI CycloneDX è pensato per casi d'uso di automazione. Tutti i comandi che hanno l'opzione --input-file supportano anche l'input da stdin. Allo stesso modo, tutti i comandi che hanno l'opzione --output-file supportano l'output su stdout. Tuttavia, dovrai specificare i formati di input/output.
Per esempio:
cat bom.json | cyclonedx-cli convert --input-format json --output-format xml > bom.xml
files
Add files to a BOM
Usage:
cyclonedx add files [options]
Options:
--input-file <input-file> Input BOM filename.
--no-input Use this option to indicate that there is no input BOM.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <autodetect|json|protobuf|xml> Specify output file format.
--base-path <base-path> Base path for directory to process (defaults to current working directory if omitted).
--include <include> Apache Ant style path and file patterns to specify what to include (defaults to all files, separate patterns with a space).
--exclude <exclude> Apache Ant style path and file patterns to specify what to exclude (defaults to none, separate patterns with a space).
Generazione di un BOM del codice sorgente, escludendo la directory del repository Git:
cyclonedx-cli add files --no-input --output-format json --exclude /.git/**
Aggiunta dei file di output di build, dalla directory bin, al BOM esistente:
cyclonedx-cli add files --input-file bom.json --output-format json --base-path bin
analyze
Analyze a BOM file
Usage:
cyclonedx analyze [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <json|text> Specify output format (defaults to text).
--multiple-component-versions Report components that have multiple versions in use.
Segnalazione dei componenti inclusi più volte con versioni diverse:
cyclonedx-cli analyze --input-file sbom.xml --multiple-component-versions
convert
Convert between different BOM formats
Usage:
cyclonedx convert [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify input file format.
--output-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify output file format.
--output-version <v1_0|v1_1|v1_2|v1_3|v1_4|v1_5|v1_6|v1_7> Specify output BOM specification version. (ignored for CSV and SPDX formats)
Conversione dal formato XML al formato JSON:
cyclonedx-cli convert --input-file sbom.xml --output-file sbom.json
Conversione dal formato XML al formato JSON e invio dell'output tramite pipe ad altri strumenti:
cyclonedx-cli convert --input-file sbom.xml --output-format json | grep "somthing"
Il formato CSV è una rappresentazione limitata dell'elenco dei componenti in un BOM.
L'intenzione è quella di fornire un modo semplice per gli utenti di produrre e consumare BOM per casi d'uso semplici. Inclusi i semplici casi d'uso di migrazione dei dati.
Gli unici campi obbligatori sono i campi name e version del componente. Gli altri
possono essere lasciati vuoti o le colonne possono essere omesse.
La conversione tra i formati SPDX e CycloneDX può comportare la perdita di alcune
informazioni. La funzionalità di conversione è fornita dalla libreria
CycloneDX.Spdx.Interop, che fa parte del progetto CycloneDX .NET library.
Per maggiori dettagli su quali informazioni vengono perse, fare riferimento alla pagina del progetto CycloneDX .NET Library.
diff
Generate a BOM diff
Usage:
cyclonedx diff <from-file> <to-file> [options]
Arguments:
<from-file> From BOM filename.
<to-file> To BOM filename.
Options:
--from-format <autodetect|json|protobuf|xml> Specify from file format.
--to-format <autodetect|json|protobuf|xml> Specify to file format.
--output-format <json|text> Specify output format (defaults to text).
--component-versions Report component versions that have been added, removed or modified.
Segnalazione dei componenti con modifiche alle versioni:
cyclonedx-cli diff sbom-from.xml sbom-to.xml --component-versions
keygen
Generates an RSA public/private key pair for BOM signing
Usage:
cyclonedx keygen [options]
Options:
--private-key-file <private-key-file> Filename for generated private key file (defaults to "private.key")
--public-key-file <public-key-file> Filename for generated public key file (defaults to "public.key")
merge
Merge two or more BOMs
Usage:
cyclonedx merge [options]