NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1816 most downloaded on Packagist
Creates CycloneDX Software Bill-of-Materials (SBOM) from PHP Composer projects
Last release 7 months ago
17 Feb 2026
Release timing varies
gaps range from 9 days to 9 months
Nearly every release is documented
notes for 45 of 49 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
52 releases · first in 2019
Migrated to cyclonedx/cyclonedx-library:^4.0 (via #619 )
cyclonedx/cyclonedx-library:^4.0 (via #619)cyclonedx/cyclonedx-library:^4.0, was :^3.9 (via #619)Full Changelog: v6.1.0...v6.2.0
One column per quarter.
Officially support PHP 8.5 ( #595 via #587 )
cyclonedx/cyclonedx-library:^3.9 (via #594)cyclonedx/cyclonedx-library:^3.9, was :^3.3 (via #594)cyclonedx/cyclonedx-library:^3.9 by @jkowalleck in #594Full Changelog: v6.0.0...v6.1.0
Fix: no longer issue git/hg commit IDs when analyzing dev-resource. ( #586 via #588 )
Full Changelog: v5.3.0...v6.0.0
Added basic support for CycloneDX Specification-1.7 .
Added basic support for CycloneDX Specification-1.7.
cyclonedx/cyclonedx-library:^3.8.cyclonedx/cyclonedx-library. (via #579)Full Changelog: v5.2.3...v5.3.0
tools(deps-dev): Update friendsofphp/php-cs-fixer requirement from 3.69.0 to 3.69.1 in /tools/php-cs-fixer by @dependabot in #532
Maintenance release.
Full Changelog: v5.2.2...v5.2.3
chore: release via GH action from softprops
chore: release via GH action from softprops
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Officially support PHP 8.4 ( #500 via #522 )
Override markers where needed (via #531)Full Changelog: v5.2.1...v5.2.2
Override markers where needed (via #531)Officially support Composer 2.8 ( #520 via #523 )
Maintenance release.
Full Changelog: v5.2.0...v5.2.1
Declared licenses are marked as such ( #474 via #479 )
cyclonedx/cyclonedx-library:^3.3, was :^3.2 (via #479)Full Changelog: v5.1.0...v5.2.0
Added basic support for CycloneDX Specification-1.6 .
Added basic support for CycloneDX Specification-1.6.
--spec-version now supports value 1.6 to reflect CycloneDX Specification-1.6 (via #477)1.5.cyclonedx/cyclonedx-library:^3.2, was :^3.1 (via #477)symfony/console:>=7 as dev-dep by @jkowalleck in #467Full Changelog: v5.0.1...v5.1.0
Applied latest PHP Coding Standards (via [#451], [#459])
CLI switch --spec-version defaults to 1.5, was 1.4 ([#442] via [#441])
Officially support PHP 8.3 (via [#342])
Maintenance release.
SBOM results might have the externalReferences[].comment populated (via [#432])
Moved all non-public API into a sub-namespace called _internal, so that its reliability is obvious. (via [#427])
_internal, so that its reliability is obvious. (via #427)SBOM result might have additional items in metadata.tools populated ([#402] via [#403]; [#404] via [#405])
Requires cyclonedx/cyclonedx-library:^2.3||^3.0, was :^2.3 (via [#398])
Added support for _CycloneDX_ Specification-1.5.
Added support for CycloneDX Specification-1.5.
Typo: "compoer" -> "composer" ([#367] via [#368])
Improved error reporting in case an invalid BOM would be created (via [#363])
Removed deprecated composer command make-bom, call composer CycloneDX:make-sbom instead ([#293] via [#309])
Based on OWASP Software Component Verification Standard for Software Bill of Materials
(SCVS SBOM) criteria, this tool is now capable of producing SBOM documents almost passing Level-2 (only signing needs to be done externally).
Affective changes based on these SCVS SBOM criteria:
<8.1 (#91, #128 via #250)<2.3 (#153 via #250)make-bom, call composer CycloneDX:make-sbom instead (#293 via #309)output-file to default to - now, which causes to print to STDOUT (via #250)exclude-dev in favor of new option omit (via #250)exclude-plugins in favor of new option omit (via #250)no-version-normalization (#102 via #250)serialnumber populated (#279 via #250, #353)metadata.timestamp populated (#112 via #250)metadata.tools[].tool.externalReferences populated (#171 via #250)components[].component.author populated (#261 via #250)components[].component.properties populated according to cdx:composer Namespace Taxonomy (#313 via #250)Nothing published for this version
Nothing published for this version
CLI via composer make-bom became deprecated, use composer CycloneDX:make-sbom instead. ([#293] via [#308]) The composer command make-bom will be remov…
Transferred copyright to OWASP Foundation. (via [#244])
Maintenance Release.
* Maintenance release.
Raised dependency cyclonedx/cyclonedx-library:^1.4.2, was :^1.3.1. (via [#192])
ExternalReferences fetched from composer's support.email are correctly prefixed with "mailto:". (via [#161]) Value was unmodified in the past.
support.email are correctly prefixed with "mailto:". (via #161)XML validation error for ExternalReference. ([#158] via [#159])
The resulting SBoM hold ExternalReferences as fetched from package descriptions. (via [#145])
Compatibility with composer v2.0.0 to v2.0.4 was improved. (via [#152])
CLI got a new switch --no-version-normalization. (via [#138]) That allows to omit component version-string normalization. Per default this plugin will
--no-version-normalization. (via #138)CLI got a new option --mc-version. (via [#133]) That allows to set the main component's version in the resulting SBoM, so that the auto-detection can
Was moved to an own package: The new external package/library is a one-to-one copy of the original code from this project. The new external package/li
Improved compatibility to composer. (via [#125]) This was made possible since composer's type hints are getting fixed. See
Added many type annotations internally, which may have an effect on CI/static analysis for people using Composer as a dependency.
Some repository data-types are lists of unique items, so no duplicates are kept. Affected classes/data-types:
ComponentRepositoryDisjunctiveLicenseRepositoryToolRepositorycomposer make-bom
BomRef model to link bom elements in general.BomRefRepository data type as a collection of unique BomRef.Component model to link components as dependencies.Component model.dependencies to XML.dependencies to JSON.docs/dev/.Will ignore "AliasPackages" when generating the SBoM, since their alias-target is part of the SBoM already.
composer make-bom
SerializersGroups will skip unsupported elements silently, instead of forwarding caught exceptions. This results in an overall smoother SBoM generatio
composer make-bom
metadata, tools, toolmetadata to XML.metadata to JSON.composer make-bom
project or composer-plugin
result as CycloneDX component of type application, was library.All informational/error output will appear on _STDERR_, was _STDOUT_. Output of the SBoM might still happen on _STDOUT_. This makes utilization of _ST
composer make-bom
--output-file=- more flexible (pipe, redirect)
whilst verbosity can be increased via -v.composer make-bom
composer-file.Added normalizer for composer.json files.
composer.json files.Per default the command will validate the resulting SBoM before writing it to file/stdOut.
composer make-bom
--no-validate to disable result validation.Deprecated switch --json was removed. Use option --output-format=JSON instead.
^7.3 || ^8.0, was ^7.1 || ^8.0.composer-plugin-api:^2.0, was composer-plugin-api:^1.1||^2.0.composer make-bom
--spec-version.--json was removed.--output-format=JSON instead.-v, -vv, -vvv.--output-file=-.--spec-version for the CycloneDX spec version.php<7.3.--json was removed.--output-format=JSON instead.package-url/packageurl-php
over own implementation.* Maintenance release.
CLI switch --json was marked as deprecated. (via [#80]) Use option --output-format=JSON instead.
Removed php-cs-fixer config from dist release.
php-cs-fixer config from dist release.Applied latest rules of php-cs-fixer to the code. (via [#78])
php-cs-fixer to the code. (via #78)Support for slim dist-builds (via [#24])
Nothing published for this version
Nothing published for this version
Nothing published for this version
Removed unneeded double forward slash from package URLs (via [#7])
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →