NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1741 most downloaded on Packagist
Work with CycloneDX documents.
Last release 20 days ago
17 Sep 2026
Ships fairly regularly
a new release about every 6 weeks
Nearly every release is documented
notes for 47 of 47 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
53 releases · first in 2021
One column per quarter.
Support CycloneDX 1.7.2 ( #657 via #658 )
Full Changelog: v4.1.0...v4.2.0
Support CycloneDX 1.7.1 ( #633 via #634 )
Full Changelog: v4.0.0...v4.1.0
BC: removed deprecated symbols by @jkowalleck in #587
CycloneDX\Contrib\License\Factories\LicenseFactoryCycloneDX\Core\Factories\LicenseFactory (#571 via #587)CycloneDX\Contrib\License\Factories\LicenseFactory instead.CycloneDX\Core\Utils\BomUtility (#571 via #587)CycloneDX\Contrib\Bom\Utils\BomUtils instead.CycloneDX\Core\Validation\BaseValidator::getSpec() (#590 via #591)CycloneDX\Contrib\License\Factories\LicenseFactory::__construct() parameters are no longer autopopulated (#571 via #587)CycloneDX\Core\Models\Component::setPackageUrl() accepts ?string (#571 via #588)CycloneDX\Core\Models\Component::getPackageUrl() returns ?string (#571 via #588)CycloneDX\Core\Validation\BaseValidator::__construct() parameter is type CycloneDX\Core\Spec\Version (#590 via #591)CycloneDX\Core\Spec\_SpecProtocol.composer/spdx-licenses:^1.5 (#571 via #587)CycloneDX\Contrib\License\Factories\LicenseFactory.Full Changelog: v3.10.0...v4.0.0
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
tests
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
normalize
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Officially support PHP 8.5 ( #566 via #574 )
Full Changelog: v3.9.0...v3.10.0
Certain exports have been deprecated; downstream imports should be updated to the new locations ( #571 via #569 ) Note: the symbols themselves remain…
\CycloneDX\Contrib (via #569)\CycloneDX\Core\Factories\LicenseFactory -> \CycloneDX\Contrib\License\Factories\LicenseFactory\CycloneDX\Core\Utils\BomUtility -> \CycloneDX\Contrib\Bom\Utils\BomUtilsFull Changelog: v3.8.0...v3.9.0
Support CycloneDX 1.7 ( #558 via #559 )
Full Changelog: v3.7.0...v3.8.0
Pulled SPDX license IDs v1.0-3.27.0 (via #553 )
Full Changelog: v3.6.0...v3.7.0
Pulled SPDX license IDs v1.0-3.26.0 (via #537 )
Full Changelog: v3.5.4...v3.6.0
tools(deps-dev): Update friendsofphp/php-cs-fixer requirement from 3.69.0 to 3.69.1 in /tools/php-cs-fixer by @dependabot in #510
Maintenance release.
Full Changelog: v3.5.3...v3.5.4
Nothing published for this version
Nothing published for this version
Nothing published for this version
Officially support PHP 8.4 ([#464] via [#488])
Override markers where needed (via #508)Applied latest PHP Coding Standards (via [#495])
Fixed the documentations of the \CycloneDX\Core\Enums classes (via [#490])
Support CycloneDX 1.6.1 ([#483] via [#484])
Encode quotation mark in URLs (via [#477])
Fixed typos in DocBlocks (via [#466])
Updated SPDX license list to v3.24.0 (via [#439])
v3.24.0 (via #439)JSON validator allow arbitrary $schema value ([#435] via [#436])
Classes \CycloneDX\Core\Serialization\{DOM,JSON}\Normalizers\LicenseNormalizer support license acknowledgement now ([#428] via [#429])
\CycloneDX\Core\Enums
\CycloneDX\Core\Models\License
Added _basic_ support for _CycloneDX_ Specification-1.6.
Added basic support for CycloneDX Specification-1.6.
\CycloneDX\Core\Spec\SpecFactory::makeForVersion() supports CycloneDX Specification-1.6 now (#421 via #422)\CycloneDX\Core\Serialization\{DOM,JSON}\Normalizers\* support CycloneDX Specification-1.6 now (#421 via #422)\CycloneDX\Core\Validation\Validators\* support CycloneDX Specification-1.6 now (#421 via #422)Rendered (API) docs are hosted on readthedocs ([#8] via [#414])
Applied latest PHP Coding Standards (via [#395], [#398], [#399], [#402])
Migration/fixup of URL(iri-reference) when normalizing to JSON (via [#380])
iri-reference) when normalizing to JSON (via #380)Officially support PHP 8.3 (via [#265])
fixed a possible JSON schema validation issue regarding "version" property (via [#352])
Interface \CycloneDX\Core\Spec\Spec was removed from public API ([#344] via [#345]) This is only a breaking change if you custom-implemented this inte…
…StaticAnalysisReport, ThreatModel, VulnerabilityAssertion
Added support for CycloneDX Specification-1.5.
\CycloneDX\Core\Spec\SpecFactory::makeForVersion() supports CycloneDX Specification-1.5 now (#193 via #255)\CycloneDX\Core\Serialization\{DOM,JSON}\Normalizers\* support CycloneDX Specification-1.5 now (#193 via #255)\CycloneDX\Core\Validation\Validators\* support CycloneDX Specification-1.5 now (#193 via #255)\CycloneDX\Core\Enums
ComponentType got new cases (#193 via #255)Data, DeviceDriver, MachineLearningModel, PlatformExternalReferenceType got new cases (#193 via #255)AdversaryModel, Attestation, CertificationReport, CodifiedInfrastructure, ComponentAnalysisReport, Configuration, DistributionIntake, DynamicAnalysisReport, Evidence, ExploitabilityStatement, Formulation, Log, MaturityReport, ModelCard, POAM, PentestReport, QualityMetrics, RiskAssessment, RuntimeAnalysisReport, SecurityContact, StaticAnalysisReport, ThreatModel, VulnerabilityAssertion\CycloneDX\Core\Spec
Class \CycloneDX\Core\Serialization\JsonSerializer
\CycloneDX\Core\Serialization\JsonSerializer
\CycloneDX\Core\Serialization\XmlSerializer
\CycloneDX\Core\Serialization\{DOM,JSON}\Normalizers\LicenseRepositoryNormalizer::normalize() now omits invalid license combinations ([#285] via [#290
Announce and annotate the generator for BOM's SerialNumber ([#277] via [#282])
"Bom.serialNumber" data model can have values following the alternative format allowed in CycloneDX XML specification ([#277] via [#278])
\CycloneDX\Core\Utils\BomUtility::randomSerialNumber() (#277 via #278)All class properties now enforce the correct types ([#6], [#114] via [#125]) This is considered a non-breaking change, because the types were already…
\CycloneDX\Core\Models\License\AbstractDisjunctiveLicense and methods that used license-related classes.
This was possible due to PHP8's UnionType language feature.\InvalidArgumentException (via #125){M,m}etaData with a capital "D" was renamed to {M,m}etadata with a small "d" (#133 via #131, #149)\CycloneDX\Core\Collections namespace
\CycloneDX\Core\Enum namespace
Classification class
ExternalReferenceType class
HashAlgorithm class
CycloneDX\Core\Factories namespace
LicenseFactory class
LicenseExpression models.composer/spdx-licenses.__construct() (via #249)makeDisjunctiveFromExpression() (#163 vial #166)setSpdxLicenseValidator() (via #249)getSpdxLicenseValidator() -> getLicenseIdentifiers() (via #249)makeDisjunctiveWithId() -> makeSpdxLicense() (#164 vial #168)makeDisjunctiveWithName() -> makeNamedLicense() (#164 vial #168)getSpdxLicenses() (via #249)\CycloneDX\Core\Models namespace
Bom class
{get,set}ComponentRepository() -> {get,set}Components() (#133 via #131){get,set}ExternalReferenceRepository() -> {get,set}ExternalReferences() (#133 via #131){get,set}MetaData() -> {get,set}Metadata() (#133 via #131){get,set}Properties() (#228 via #229){get,set}SerialNumber() (via #186)Component class
{get,set}DependenciesBomRefRepository() -> {get,set}Dependencies() (#133 via #131){get,set}ExternalReferenceRepository() -> {get,set}ExternalReferences() (#133 via #131){get,set}HashRepository() -> {get,set}Hashes() (#133 via #131){get,set}License() -> {get,set}Licenses() (via #131)LicenseRepository only, was working with various Models\License\* types (#66 via #131)version to be optional, to reflect CycloneDX v1.4 (#27 via #118, #131){get,set}Version().type to be of type \CycloneDX\Core\Enum\ComponentType (#140 via #204){get,set}Type().{get,set}Author() ([#184] via #185){get,set}Copyright() (#238 via #239){get,set}Evidence() (#238 via #241){get,set}Properties() (#228 via #165)ComponentEvidence (#238 via #241)ExternalReference class
{get,set}HashRepository() -> {get,set}Hashes() (#133 via #131)type to be of type \CycloneDX\Core\Enum\ExternalReferenceType (#140 via #204){get,set}Type().Licenses namespace
AbstractDisjunctiveLicense
DisjunctiveLicenseWithName class
DisjunctiveLicenseWithId class
SpdxLicense (#164 via #168)makeValidated() (#247 via #249)
To assert valid values use \CycloneDX\Core\Factories\LicenseFactory::makeSpdxLicense().__construct() is public now, was private (#247 via #249)setId() (#247 via #249)LicenseExpression class
MetaData class
Metadata (#133 via #131){get,set}Tools() so that their parameter & return type is non-nullable, was nullable (#66 via #131){get,set}Properties() (#228 via #165){get,set}Timestamp() (via #180, #181)Property (#228 via #165)Tool class
{get,set}ExternalReferenceRepository() -> {get,set}ExternalReferences() (#133 via #131){get,set}HashRepository() -> {get,set}Hashes() (#133 via #131)\CycloneDX\Core\Repositories namespace
DisjunctiveLicenseRepository class
\CycloneDX\Core\Collections\LicenseRepository (via #131)Models\LicenseExpression (via #131)\CycloneDX\Core\Models\License\AbstractDisjunctiveLicense only.HashRepository class
\CycloneDX\Core\Collections\HashDictionary (#133 via #131)\CycloneDX\Core\Enum\HashAlgorithm (#140 via #204)\CycloneDX\Core\Serialize namespace
SerializerInterface interface
BaseSerializer abstract class
{Json,Xml}Serializer class
{DOM,JSON}\NormalizerFactory classes
makeForLicenseExpression() (via #131)makeForDisjunctiveLicense() (via #131)makeForDisjunctiveLicenseRepository() (via #131)makeForHashRepositonary() - use makeForHashDictionary() instead (#133 via #131)setSpec() (via #131)makeForComponentEvidence() (#238 via #241)makeForHashDictionary() (#133 via #131)makeForLicense() (via #131)makeForLicenseRepository() (via #131){DOM,JSON}\Normalizers namespaces
DisjunctiveLicenseNormalizer - use LicenseNormalizer instead (via #131)LicenseExpressionNormalizer - use LicenseNormalizer instead (via #131)DisjunctiveLicenseRepositoryNormalizer (via #131)HashRepositoryNormalizer -> HashDictionaryNormalizer (#133 via #131)Models\HashDictionary instead of Models\HashRepositoryHashNormalizer to accept native PHP Enumeration type \CycloneDX\Core\Enum\HashAlgorithm (#140 via #204)ComponentEvidenceNormalizer that can normalize ComponentEvidence (#238 via #241)LicenseNormalizer that can normalize every existing license model (via #131)LicenseRepositoryNormalizer that can normalize LicenseRepository (via #131)ExternalReferenceNormalizer classes
normalize() to actually throw \DomainException when \ExternalReference's type was not supported by the spec (via #65)ExternalReferenceNormalizer classes
JSON\Normalizers\BomNormalizer class
normalize()'s result data may contain the $schema string (via #155)JSON\Normalizers\ExternalReferenceNormalizer class
normalize() may throw \UnexpectedValueException when the url is invalid to format "ini-reference" (via #151)\CycloneDX\Core\Spdx namespace
License -> LicenseIdentifiers (#133 via #143, #249)getLicense() -> fixLicense() (via #249)getLicenses() -> getKnownLicenses(), and removed keys from return value (via #249)validate() -> isKnownLicense() (via #249)\CycloneDX\Core\Spec namespace
\CycloneDX\Core\Validation namespace
BaseValidator class
setSpec() (via #144)ValidatorInterface interface
Validators\{Json,JsonStrict,Xml}Validator classes
Validators\{Json,JsonStrict}Validator classes
Nothing published for this version
Transferred copyright to OWASP Foundation. (via [#121])
Maintenance Release.
Added "Responsibilities", "Capabilities" and "Usage" sections to README. (via [#115])
Maintenance release.
* Maintenance release.
Use [version 9b04a94 of CycloneDX specification][CDX-specification#9b04a94474dfcabafe7d3a9f8db6c7e5eb868adb] for XML and JSON schema validation. (via
Use [version 82bf9e3 of CycloneDX specification][CDX-specification#82bf9e30ba3fd6413e72a0e66adce2cdf3354f32] for XML and JSON schema validation. (via
Return type of CycloneDX\Core\Serialize\SerializerInterface::serialize() and implementations/usage are documented as non-empty-string, were undocument
CycloneDX\Core\Serialize\SerializerInterface::serialize() and implementations/usage
are documented as non-empty-string, were undocumented string before. (via #70)CycloneDX\Core\Validation\ValidatorInterface::validateString() and implementations are documented as non-empty-string, were undocumented string before
CycloneDX\Core\Validation\ValidatorInterface::validateString() and implementations
are documented as non-empty-string, were undocumented string before. (via #63)Resulting JSON files hold the correct $schema. ([#43] via [#42])
XML serializer & DOM normalizer no longer generate invalid XML::anyURI. (via [#34])
XML::anyURI. (via #34)JSON result does no longer have slashes escaped in strings. (via [#33]) Old: "http:\/\/exampe.com" New: "http://exampe.com"
"http:\/\/exampe.com""http://exampe.com"Prevention of information-loss on metadata-component's ExternalReferences, when normalizing to a specification that does not support bom.metadata (via
bom.metadata
(via #26)Support for ExternalReferences in BOM and Component (via [#17])
CycloneDX\Core\Models\License\AbstractDisjunctiveLicense::setUrl() no longer restricts the argument to be a valid URL. Per schema definition licenseTy
CycloneDX\Core\Models\License\AbstractDisjunctiveLicense::setUrl() no longer restricts the argument to be a valid URL.licenseType.url should be a URI, not a URL.
See #18CycloneDX\Core\Models\License\AbstractDisjunctiveLicense::setUrl() no longer throws InvalidArgumentException
if the argument is not a URL (via #19)Psalm-annotation of CycloneDX\Core\Enums\Classification::isValidValue() (via [#10])
CycloneDX\Core\Enums\Classification::isValidValue() (via #10)Removed composer's conflict constraint. This was done to enable some workflows with package forks/mirrors that don't have proper version detection. Se
Removed composer's conflict constraint.
This was done to enable some workflows with package forks/mirrors that don't have proper version detection.
See #9
Initial release. Split the library from `/src/Core` of cyclonedx-php-composer
Initial release.
Split the library from
/src/Core of cyclonedx-php-composer (346e6200fb2f5086061b15c2ee44f540893ce97d)
Your coding agent can read these notes before it upgrades. Set up the MCP server →