
JSON, XML, Protobuf, CSV 및 SPDX 형식의 CycloneDX SBOM을 생성, 분석, 병합, 비교, 검증, 서명 및 변환하기 위한 CLI입니다.
______ __ ____ _ __ ________ ____
/ ____/_ _______/ /___ ____ ___ / __ \ |/ / / ____/ / / _/
/ / / / / / ___/ / __ \/ __ \/ _ \/ / / / / / / / / / /
/___/ /_/ / /__/ / /_/ / / / / __/ /_/ / | / /___/ /____/ /
\____/\__, /\___/_/\____/_/ /_/\___/_____/_/|_| \____/_____/___/
/____/
Usage:
cyclonedx [command] [options]
Options:
--version Show version information
-?, -h, --help Show help and usage information
Commands:
add Add information to a BOM (currently supports files)
analyze Analyze a BOM file
convert Convert between different BOM formats
diff <from-file> <to-file> Generate a BOM diff
keygen Generates an RSA public/private key pair for BOM signing
merge Merge two or more BOMs
sign Sign a BOM or file
validate Validate a BOM
verify Verify signatures in a BOM
CycloneDX CLI 도구는 현재 BOM 분석, 수정, diff, 병합, 형식 변환, 서명 및 검증을 지원합니다.
CycloneDX XML, JSON, Protobuf, CSV 및 SPDX JSON v2.3 간의 변환이 지원됩니다.
바이너리는 릴리스 페이지에서 다운로드할 수 있습니다.
참고: CycloneDX CLI 도구는 자동화 사용 사례를 위해 제작되었습니다. --input-file 옵션이 있는 모든 명령은 stdin에서 입력을 받는 것도 지원합니다. 마찬가지로 --output-file 옵션이 있는 모든 명령은 stdout으로 출력을 지원합니다. 단, 입력/출력 형식을 지정해야 합니다.
예를 들어:
cat bom.json | cyclonedx-cli convert --input-format json --output-format xml > bom.xml
files
Add files to a BOM
Usage:
cyclonedx add files [options]
Options:
--input-file <input-file> Input BOM filename.
--no-input Use this option to indicate that there is no input BOM.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <autodetect|json|protobuf|xml> Specify output file format.
--base-path <base-path> Base path for directory to process (defaults to current working directory if omitted).
--include <include> Apache Ant style path and file patterns to specify what to include (defaults to all files, separate patterns with a space).
--exclude <exclude> Apache Ant style path and file patterns to specify what to exclude (defaults to none, separate patterns with a space).
Git 저장소 디렉터리를 제외한 소스 코드 BOM 생성:
cyclonedx-cli add files --no-input --output-format json --exclude /.git/**
기존 BOM에 bin 디렉터리의 빌드 출력 파일 추가:
cyclonedx-cli add files --input-file bom.json --output-format json --base-path bin
analyze
Analyze a BOM file
Usage:
cyclonedx analyze [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <json|text> Specify output format (defaults to text).
--multiple-component-versions Report components that have multiple versions in use.
서로 다른 버전으로 여러 번 포함된 컴포넌트 보고:
cyclonedx-cli analyze --input-file sbom.xml --multiple-component-versions
convert
Convert between different BOM formats
Usage:
cyclonedx convert [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify input file format.
--output-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify output file format.
--output-version <v1_0|v1_1|v1_2|v1_3|v1_4|v1_5|v1_6|v1_7> Specify output BOM specification version. (ignored for CSV and SPDX formats)
XML에서 JSON 형식으로 변환:
cyclonedx-cli convert --input-file sbom.xml --output-file sbom.json
XML에서 JSON 형식으로 변환하고 출력을 추가 도구로 파이프:
cyclonedx-cli convert --input-file sbom.xml --output-format json | grep "somthing"
CSV 형식은 BOM에 있는 컴포넌트 목록의 제한된 표현입니다.
목적은 사용자가 간단한 사용 사례를 위해 BOM을 손쉽게 생성하고 소비할 수 있는 방법을 제공하는 것입니다. 간단한 데이터 마이그레이션 사용 사례도 포함됩니다.
필수 필드는 컴포넌트 name 및 version 필드뿐입니다. 나머지 필드는 비워 두거나 열을 생략할 수 있습니다.
SPDX와 CycloneDX 형식 간 변환 시 일부 정보가 손실될 수 있습니다. 변환 기능은 CycloneDX .NET 라이브러리 프로젝트의 일부인 CycloneDX.Spdx.Interop 라이브러리에서 제공됩니다.
어떤 정보가 손실되는지에 대한 자세한 내용은 CycloneDX .NET 라이브러리 프로젝트 페이지를 참조하세요.
diff
Generate a BOM diff
Usage:
cyclonedx diff <from-file> <to-file> [options]
Arguments:
<from-file> From BOM filename.
<to-file> To BOM filename.
Options:
--from-format <autodetect|json|protobuf|xml> Specify from file format.
--to-format <autodetect|json|protobuf|xml> Specify to file format.
--output-format <json|text> Specify output format (defaults to text).
--component-versions Report component versions that have been added, removed or modified.
버전 변경이 있는 컴포넌트 보고:
cyclonedx-cli diff sbom-from.xml sbom-to.xml --component-versions
keygen
Generates an RSA public/private key pair for BOM signing
Usage:
cyclonedx keygen [options]
Options:
--private-key-file <private-key-file> Filename for generated private key file (defaults to "private.key")
--public-key-file <public-key-file> Filename for generated public key file (defaults to "public.key")
merge
Merge two or more BOMs
Usage:
cyclonedx merge [options]
Options:
--input-files <input-files> Input BOM filenames (separate filenames with a space).
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <autodetect|json|protobuf|xml> Specify output file format.
--output-version <v1_0|v1_1|v1_2|v1_3|v1_4|v1_5|v1_6|v1_7> Specify output BOM specification version.
--hierarchical Perform a hierarchical merge.
--group <group> Provide the group of software the merged BOM describes.
--name <name> Provide the name of software the merged BOM describes (required for hierarchical merging).
--version <version> Provide the version of software the merged BOM describes (required for hierarchical merging).
참고: 계층적 병합을 수행하려면 모든 BOM의 metadata component 요소에 BOM의 대상(subject)이 설명되어 있어야 합니다.
두 개의 XML 형식 BOM 병합:
cyclonedx-cli merge --input-files sbom1.xml sbom2.xml --output-file sbom_all.xml