# cdxgen/cdxgen

Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server

Repository: https://github.com/cdxgen/cdxgen
Canonical: https://ross.abutalabs.com/products/cdxgen
Homepage: https://cdxgen.github.io/cdxgen/
Language: JavaScript
License: Apache-2.0
License Family: permissive
Topics: bom, sca, cyclonedx, sbom, docker, oci, containers, owasp, package-url, purl, software-bill-of-materials, saasbom, supply-chain, cbom, spdx, spdx-sbom
Last push: 2026-09-03T01:49:16+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 100, release rhythm 86, longevity 100
- inputs: {"age_days": 2438, "days_push": 0, "days_rel": 15, "gap_med": 5, "n_releases_24m": 90}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1060, forks 260 (observed 2026-09-03T02:15:09.903677+00:00)

## What it is
cdxgen is a CLI tool, library, and server that creates CycloneDX Bill of Materials (SBOM) documents from source code and container images, supporting many languages and package managers. It also generates hardware, cryptography, operations, SaaS, and AI/ML BOMs, supports SPDX export, and integrates with CI/CD pipelines including Dependency-Track submission.

## Use cases
- generate an sbom for my project
- create cyclonedx bom from a docker image
- produce software bill of materials in ci pipeline
- export spdx sbom for compliance
- inventory cryptography used in my java app
- submit sbom to dependency-track automatically
- generate ai bom for my llm project

## When to choose
- you need standards-compliant CycloneDX or SPDX SBOMs across many languages and package managers
- you want to scan container images or live hosts for BOM generation
- you need CI/CD integration with automatic Dependency-Track submission
- you need specialized BOMs like CBOM, OBOM, SaaSBOM, or AI-BOM

## When to avoid
- you only need vulnerability scanning without BOM generation (use OWASP depscan instead)
- you need a GUI-based SBOM tool
- your ecosystem is unsupported by cdxgen's language analyzers

## Facets
- artifact type: cli-tool
- maturity: active
- function: developer-tools, security, dependency-audit, cli, container-runtime, ci-cd
- domain: security, developer-tools
- platform: cli, cross-platform, windows
- tags: sbom, cyclonedx, spdx, bom, software-composition-analysis, supply-chain-security, package-url, cbom, obom, saasbom, ai-bom, devops, containers, supply-chain, nodejs, docker, linux, macos

## Member repositories
- cdxgen/cdxgen (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-09-03T02:15:09.903677+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:00:17.275115+00:00, confidence not recorded.
  - readme: https://github.com/cdxgen/cdxgen (fetched 2026-09-03T02:15:09.903677+00:00, sha f80ca272c3c3)
  - homepage: https://cdxgen.github.io/cdxgen/ (fetched 2026-08-29T13:01:31.608081+00:00, sha 55bcf678a29b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
