cdxgen is a CLI tool, library, REPL, and server to create, validate, sign, and verify software BOMs. It generates CycloneDX JSON BOMs and supports SPDX 3.0.1 JSON-LD export.
> /plugin marketplace add cdxgen/cdxgen> /plugin install cdxgen@cdxgen-plugins
Repo: cdxgen/cdxgen
What's inside
[![JSR][badge-jsr]][jsr-cdxgen]
[![NPM][badge-npm]][npmjs-cdxgen]
[![GitHub Releases][badge-github-releases]][github-releases]
[![NPM Downloads][badge-npm-downloads]][npmjs-cdxgen]
[![GitHub License][badge-github-license]][github-license]
[![GitHub Contributors][badge-github-contributors]][github-contributors]
[![SWH][badge-swh]][swh-cdxgen]
cdxgen is a CLI tool, library, REPL, and server to create, validate, sign, and verify software BOMs. It generates CycloneDX JSON BOMs and supports SPDX 3.0.1 JSON-LD export. CycloneDX is a full-stack BOM specification that is easily created, human and machine-readable, and simple to parse. The tool generates BOMs targeting CycloneDX specification versions 1.6, 1.7, and 2.0, and the output can be downgraded to 1.4 or 1.5 for legacy consumers.
Supported BOM formats:
Supported output document formats:
cdxgen --format spdx or cdx-convert)| Persona | What cdxgen helps you do | First command | Read next |
|---|---|---|---|
| Developers | Generate a CycloneDX BOM from a local repo, git URL, purl, or container image | cdxgen -o bom.json . | [CLI Usage][docs-cli], [Supported Project Types][docs-project-types] |
| AI platform teams | Generate AI/ML BOMs, catalog prompt/model/MCP surfaces, and run AI-BOM governance | aibom . | AI-BOM Guide, AI-BOM lesson |
| Hardware teams | Generate an HBOM or merged HBOM+OBOM host view for the current host | hbom -o hbom.json | HBOM guide, HBOM lesson |
| AppSec | Enrich BOMs with evidence, run BOM audit rules, and feed downstream security workflows | cdxgen -o bom.json --profile appsec --evidence --bom-audit . | BOM Audit, Threat Model |
| Build engineers | Grade how completely the SBOM captured the project, and get ranked fixes when the build environment degraded it | cdxgen --profile introspect --introspect-fail-below 70 -o bom.json . | Build Introspection, Fidelity loop skill |
| SOC analysts | Build OBOM inventories for live hosts and triage runtime posture issues | obom -o obom.json --deep --bom-audit --bom-audit-categories obom-runtime | OBOM lessons, [Server Usage][docs-server] |
| Compliance teams | Validate BOM quality, check SCVS/CRA posture, and export SPDX deliverables | cdx-validate -i bom.json --benchmark scvs-l2,cra | cdx-validate, cdx-convert, [Permissions][docs-permissions] |
| Security Teams | Dynamically trace executions to capture cryptographic activities, CBOM properties, software components, and services | tracebom --cmd "npm test" --trace-crypto -o cbom.json | Threat Model |
hbom when you need a CycloneDX hardware inventory for the current host rather than a software dependency graph.hbom --dry-run first when you want a read-only partial HBOM plus an exact list of blocked hardware probe commands before a full collection run.hbom diagnostics when you want a focused summary of missing native utilities and permission-denied enrichments before deciding whether to install host packages or rerun with --privileged.hbom --include-runtime when you want one topology-aware CycloneDX host document that merges hardware inventory with runtime evidence using strict, non-guessing joins.--profile appsec, --evidence, and --bom-audit when you want richer security context.tracebom to dynamically profile applications & services and capture negotiated TLS cipher suites, protocols, cryptographic libraries, dynamically resolved software components, and services in CycloneDX 1.7 format.--include-formulation plus --bom-audit --bom-audit-categories ai-bom when you want one AI-BOM workflow for prompt files, AI services, MCP configs, and model metadata.aibom when you want the same defaults in one dedicated CLI, including direct Hugging Face purls/URLs and direct Modelfile / .gguf inputs.obom for live-system and runtime inventory on Linux, Windows, and macOS hosts.cdx-validate to assess structural and compliance posture, then cdx-convert when SPDX output is required.Most SBOM tools are like simple barcode scanners. For easy applications, they can parse a few package manifests and create a list of components only based on these files without any deep inspection. Further, a typical application might have several repos, components, and libraries with complex build requirements. Traditional techniques to generate an SBOM per language or package manifest either do not work in enterprise environments or don't provide the confidence required for both compliance and automated analysis. So we built cdxgen - the universal polyglot SBOM generator that is user-friendly, precise, and comprehensive!
Our philosophy:
--dry-run mode for review-first workflows.Please visit our [documentation site][docs-homepage] for detailed usage, tutorials, and support documentation.
Sections include:
[!IMPORTANT] The npm package was renamed in v13. v13 and later are published as [
@cdxgen/cdxgen][npmjs-cdxgen]. v12 and earlier are published as [@cyclonedx/cdxgen][npmjs-cdxgen-v12], which stays on npm and continues to receive fixes on therelease/12.0.xbranch, but does not receive v13 features.Upgrading means changing the package name, not just the version:
npm uninstall -g @cyclonedx/cdxgen npm install -g @cdxgen/cdxgen --ignore-scripts --min-release-age=2The
cdxgencommand, the CLI flags, and the container images are unchanged. If you import cdxgen as a library, update the specifier:import { createBom } from "@cdxgen/cdxgen".
cdxgen is distributed three ways. The standalone executables and container images are the recommended choice for CI, production, and any environment where you want a self-contained tool with no Node.js dependency. The npm package is an alternative when you already manage JavaScript tooling or need cdxgen as a
Showing a partial view of a very large repo.
FAQ
cdxgen is a Claude Code plugin with 14 hand-picked skills for security work, indexed on Flowy. Install it with the command on its page. It includes ai-bom, bom-audit, bom-convert-validate. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.
Is this plugin yours?
Claim it with GitHubSubmit a pluginPromote it