Ross ROSS = Recommend OSS · open-source software intelligence for agents

cdxgen/cdxgen

Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server observed · 2026-09-03

github.com/cdxgen/cdxgen · homepage · JavaScript · Apache-2.0 (permissive) observed · 2026-09-03

Health v2 · maintenance only

95/100

  • Activity 100
  • Release rhythm 86
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 5
  • age_days: 2438
  • days_rel: 15
  • days_push: 0
  • n_releases_24m: 90

Full methodology

Adoption not part of the score

1060 stars · 260 forks observed · 2026-09-03

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

cdxgen is a CLI tool, library, and server that creates CycloneDX Bill of Materials (SBOM) documents from source code and container images, supporting many languages and package managers. It also generates hardware, cryptography, operations, SaaS, and AI/ML BOMs, supports SPDX export, and integrates with CI/CD pipelines including Dependency-Track submission.

Use cases

  • generate an sbom for my project
  • create cyclonedx bom from a docker image
  • produce software bill of materials in ci pipeline
  • export spdx sbom for compliance
  • inventory cryptography used in my java app
  • submit sbom to dependency-track automatically
  • generate ai bom for my llm project

When to choose

  • you need standards-compliant CycloneDX or SPDX SBOMs across many languages and package managers
  • you want to scan container images or live hosts for BOM generation
  • you need CI/CD integration with automatic Dependency-Track submission
  • you need specialized BOMs like CBOM, OBOM, SaaSBOM, or AI-BOM

When to avoid

  • you only need vulnerability scanning without BOM generation (use OWASP depscan instead)
  • you need a GUI-based SBOM tool
  • your ecosystem is unsupported by cdxgen's language analyzers

Facets

cli-tool · maturity active

developer-tools security dependency-audit cli container-runtime ci-cd security developer-tools cli cross-platform windows sbom cyclonedx spdx bom software-composition-analysis supply-chain-security package-url cbom obom saasbom ai-bom devops containers supply-chain nodejs docker linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
cdxgen/cdxgenmain95

For agents

markdown · JSON · MCP: product_card(name="cdxgen/cdxgen")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem