______ __ ____ _ __ ________ ____
/ ____/_ _______/ /___ ____ ___ / __ \ |/ / / ____/ / / _/
/ / / / / / ___/ / __ \/ __ \/ _ \/ / / / / / / / / / /
/ /___/ /_/ / /__/ / /_/ / / / / __/ /_/ / | / /___/ /____/ /
\____/\__, /\___/_/\____/_/ /_/\___/_____/_/|_| \____/_____/___/
/____/
Usage:
cyclonedx [command] [options]
Options:
--version Show version information
-?, -h, --help Show help and usage information
Commands:
add Add information to a BOM (currently supports files)
analyze Analyze a BOM file
convert Convert between different BOM formats
diff <from-file> <to-file> Generate a BOM diff
keygen Generates an RSA public/private key pair for BOM signing
merge Merge two or more BOMs
sign Sign a BOM or file
validate Validate a BOM
verify Verify signatures in a BOM
CycloneDX CLI 工具目前支持 BOM 分析、修改、差异比较、合并、格式转换、签名和验证。
支持在 CycloneDX XML、JSON、Protobuf、CSV 和 SPDX JSON v2.3 之间进行转换。
可以从发布页面下载二进制文件。
注意:CycloneDX CLI 工具专为自动化用例而构建。任何带有 --input-file 选项的命令都支持从 stdin 读取输入;同样,任何带有 --output-file 选项的命令都支持将输出写入 stdout。但是,您需要指定输入/输出格式。
例如:
cat bom.json | cyclonedx-cli convert --input-format json --output-format xml > bom.xml
files
Add files to a BOM
Usage:
cyclonedx add files [options]
Options:
--input-file <input-file> Input BOM filename.
--no-input Use this option to indicate that there is no input BOM.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <autodetect|json|protobuf|xml> Specify output file format.
--base-path <base-path> Base path for directory to process (defaults to current working directory if omitted).
--include <include> Apache Ant style path and file patterns to specify what to include (defaults to all files, separate patterns with a space).
--exclude <exclude> Apache Ant style path and file patterns to specify what to exclude (defaults to none, separate patterns with a space).
生成源代码 BOM,排除 Git 仓库目录:
cyclonedx-cli add files --no-input --output-format json --exclude /.git/**
将 bin 目录中的构建输出文件添加到现有 BOM:
cyclonedx-cli add files --input-file bom.json --output-format json --base-path bin
analyze
Analyze a BOM file
Usage:
cyclonedx analyze [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <json|text> Specify output format (defaults to text).
--multiple-component-versions Report components that have multiple versions in use.
报告以不同版本被多次包含的组件:
cyclonedx-cli analyze --input-file sbom.xml --multiple-component-versions
convert
Convert between different BOM formats
Usage:
cyclonedx convert [options]
Options:
--input-file <input-file> Input BOM filename, will read from stdin if no value provided.
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify input file format.
--output-format <autodetect|csv|json|protobuf|spdxjson|xml> Specify output file format.
--output-version <v1_0|v1_1|v1_2|v1_3|v1_4|v1_5|v1_6|v1_7> Specify output BOM specification version. (ignored for CSV and SPDX formats)
从 XML 格式转换为 JSON 格式:
cyclonedx-cli convert --input-file sbom.xml --output-file sbom.json
从 XML 格式转换为 JSON 格式,并将输出通过管道传递给其他工具:
cyclonedx-cli convert --input-file sbom.xml --output-format json | grep "somthing"
CSV 格式是 BOM 中组件列表的一种有限表示形式。
其目的是为用户提供一种简单的方式,以便在简单的使用场景中生成和使用 BOM,包括简单的数据迁移场景。
唯一必填字段是组件的 name 和 version 字段。其他字段可以留空,也可以省略对应列。
在 SPDX 和 CycloneDX 格式之间进行转换可能会导致某些信息丢失。转换功能由 CycloneDX.Spdx.Interop 库提供,该库是 CycloneDX .NET 库项目的一部分。
有关哪些信息会丢失的更多详情,请参阅 CycloneDX .NET 库项目页面。
diff
Generate a BOM diff
Usage:
cyclonedx diff <from-file> <to-file> [options]
Arguments:
<from-file> From BOM filename.
<to-file> To BOM filename.
Options:
--from-format <autodetect|json|protobuf|xml> Specify from file format.
--to-format <autodetect|json|protobuf|xml> Specify to file format.
--output-format <json|text> Specify output format (defaults to text).
--component-versions Report component versions that have been added, removed or modified.
报告发生版本变化的组件:
cyclonedx-cli diff sbom-from.xml sbom-to.xml --component-versions
keygen
Generates an RSA public/private key pair for BOM signing
Usage:
cyclonedx keygen [options]
Options:
--private-key-file <private-key-file> Filename for generated private key file (defaults to "private.key")
--public-key-file <public-key-file> Filename for generated public key file (defaults to "public.key")
merge
Merge two or more BOMs
Usage:
cyclonedx merge [options]
Options:
--input-files <input-files> Input BOM filenames (separate filenames with a space).
--output-file <output-file> Output BOM filename, will write to stdout if no value provided.
--input-format <autodetect|json|protobuf|xml> Specify input file format.
--output-format <autodetect|json|protobuf|xml> Specify output file format.
--output-version <v1_0|v1_1|v1_2|v1_3|v1_4|v1_5|v1_6|v1_7> Specify output BOM specification version.
--hierarchical Perform a hierarchical merge.
--group <group> Provide the group of software the merged BOM describes.
--name <name> Provide the name of software the merged BOM describes (required for hierarchical merging).
--version <version> Provide the version of software the merged BOM describes (required for hierarchical merging).
注意:要执行分层合并,所有 BOM 都需要在 metadata component 元素中描述 BOM 的主题。
合并两个 XML 格式的 BOM:
cyclonedx-cli merge --input-files sbom1.xml sbom2.xml --output-file sbom_all.xml
合并两个 BOM,并将输出通过管道传递给其他工具:
cyclonedx-cli merge --input-files sbom1.xml sbom2.xml --output-format json | grep "something"
对 BOM 或文件进行签名
bom
Sign the entire BOM document
Usage:
cyclonedx sign bom <bom-file> [options]