NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #2771 most downloaded on NuGet
A .NET Core global tool to generate CycloneDX bill-of-material documents for use with Software Composition Analysis (SCA).
Last release 5 months ago
27 Apr 2026
Ships fairly regularly
a new release about every 6 weeks
Rarely documented
notes for 10 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
77 releases · first in 2018
Suppress aka.ms/deprecateLicenseUrl stub URL ( #1011 ) — NuGet auto-injects https://aka.ms/deprecateLicenseUrl\ into for packages packed with ; this U…
Thanks to everyone who contributed to this release:
One column per quarter.
--configuration / -c CLI option (#1056, fixes #1028) — passes -p:Configuration=<value> to dotnet restore so MSBuild evaluates conditional PackageReference items during restore. Configuration-specific packages (e.g. debug-only Avalonia.Diagnostics) are no longer included in the SBOM when a Release configuration is requested.<license type="file"> now have their license file embedded as base64-encoded text in the BOM when --include-license-text is specified; without the flag the license is still detected but not embeddedaka.ms/deprecateLicenseUrl stub URL (#1011) — NuGet auto-injects https://aka.ms/deprecateLicenseUrl into <licenseUrl> for packages packed with <license type="file">; this URL is now correctly ignored rather than being emitted as a license entry in the BOM (see NuGet spec)<licenseUrl> no longer produce a spurious License { Name="Unknown - See URL", Url=null } node in the BOMUNLICENSED emitted as SPDX id (#1004, fixes #915) — UNLICENSED is a NuGet-specific token that is not a valid SPDX identifier; it is now emitted as license.name instead of license.id to keep BOM output validconfiguration parameter with method overloads — addresses Codacy "Use the overloading mechanism instead of the optional parameters" findings on IDotnetUtilsService.Restore, IProjectFileService.GetProjectDotnetDependencysAsync / RecursivelyGetProjectDotnetDependencysAsync, and ISolutionFileService.GetSolutionDotnetDependencysUtils.UseUnsafeRelaxedJsonEscaping global flagsetup-dotnet steps to avoid macOS timeoutdocs/license-resolution.md) — documents the four-phase license resolution pipeline used by the tool--configuration — new Verify-based BOM snapshot tests covering TestPkg.UrlLicense, TestPkg.SpdxLicense, TestPkg.FileLicense, and conditional PackageReference scenarios with and without the --configuration flagFix crash when a nuspec declares an exact-range version constraint across multiple projects ( #1071 ) — when a package's nuspec dependency uses an exa
[1.0.0]) and multiple versions of that package are present in a multi-project solution, the tool no longer crashes with "Unable to locate valid bom ref"; the dependency edge is resolved to the version that satisfies the rangeUse tools/components instead of deprecated tools/tool ( #1043 ) — BOM metadata now uses the non-deprecated CycloneDX structure for recording tool info…
bom/1.7 schema namespace--exclude filter no longer requires a version to be specifiedAssemblyName in projects using the default XML namespacetools/components instead of deprecated tools/tool (#1043) — BOM metadata now uses the non-deprecated CycloneDX structure for recording tool information⚠️ WARNING: This is a MAJOR release with breaking changes.
⚠️ WARNING: This is a MAJOR release with breaking changes.
This release includes multiple significant changes that may affect compatibility:
- Removed deprecated CLI arguments - Several CLI flags have been removed. Scripts, CI/CD pipelines, and automation using these flags will break.
- Upgraded to .NET 10 - Runtime requirements have changed.
- Updated System.CommandLine - Upgraded from beta4 to v2.0.0 final, which includes breaking API changes that may affect command-line behavior.
- Updated dependency versions - NuGet packages, System.IO.Abstractions, and other dependencies have been upgraded.
Action required: Test thoroughly in a non-production environment before upgrading. Review all sections below for changes that may affect your use case.
Remove deprecated CLI arguments (#996, 0ae5d6a)
-f flag (replaced by -fn/--filename)-d flag (replaced by -ed/--exclude-dev)-r flag (replaced by -rs/--scan-project-references)--disable-github-licenses/-dgl flag (already default behavior)--out and --json flag were not removed in this release for backward compatibility but are still deprecated and will be removed in a future release.Upgraded System.CommandLine to v2.0.0 (#989, e11f8e7)
2.0.0-beta4.22272.1 to 2.0.0 (stable release)Minimum .NET runtime requirement (#989, e11f8e7)
mcr.microsoft.com/dotnet/sdk:10.0Dockerfile improvements (#993, edf2bd9)
DOTNET_CLI_HOME, NUGET_PACKAGES/tmp/dotnet-home and /tmp/nuget-packages writable for any user (chmod 0755)CycloneDX to dotnet /app/CycloneDX.dllpath argument optional with ArgumentArity.ZeroOrOneUpgrade to .NET 10 (#989, e11f8e7)
net10.0mcr.microsoft.com/dotnet/sdk:10.0Dependency updates
Workflow security hardening (#975, 39b8986)
permissions: contents: read to permissions: read-allPin GitHub Actions versions (1145c82)
Enable NuGet package locking (#972, fad44df)
packages.lock.json files for both main and test projectsRestorePackagesWithLockFile in Directory.Build.propsUpdate NuGet dependencies (#973, e930da1)
NuGet.ProjectModel from 6.9.1 to 6.14.0NuGet.Protocol from 6.9.1 to 6.14.0⚠️ WARNING: This is a MAJOR release with breaking changes.
This release includes multiple significant changes that may affect compatibility:
- Removed deprecated CLI arguments - Several CLI flags have been removed. Scripts, CI/CD pipelines, and automation using these flags will break.
- Upgraded to .NET 10 - Runtime requirements have changed.
- Updated System.CommandLine - Upgraded from beta4 to v2.0.0 final, which includes breaking API changes that may affect command-line behavior.
- Updated dependency versions - NuGet packages, System.IO.Abstractions, and other dependencies have been upgraded.
Action required: Test thoroughly in a non-production environment before upgrading. Review all sections below for changes that may affect your use case.
Remove deprecated CLI arguments (#996, 0ae5d6a)
--json/-j flag (replaced by --output-format json)-f flag (replaced by -fn/--filename)-d flag (replaced by -ed/--exclude-dev)-r flag (replaced by -rs/--scan-project-references)--disable-github-licenses/-dgl flag (already default behavior)json property from RunOptions modeloutputFormat enum instead of boolean json flagProgram.cs and Runner.cs--out flag was restored before release for backward compatibility (see Fixed section below)Upgraded System.CommandLine to v2.0.0 (#989, e11f8e7)
2.0.0-beta4.22272.1 to 2.0.0 (stable release)Minimum .NET runtime requirement (#989, e11f8e7)
mcr.microsoft.com/dotnet/sdk:10.0.slnx format to supported file types in READMEDockerfile improvements (#993, edf2bd9)
DOTNET_CLI_HOME, NUGET_PACKAGES/tmp/dotnet-home and /tmp/nuget-packages writable for any user (chmod 0755)CycloneDX to dotnet /app/CycloneDX.dllpath argument optional with ArgumentArity.ZeroOrOneUpgrade to .NET 10 (#989, e11f8e7)
net10.0mcr.microsoft.com/dotnet/sdk:10.0Dependency updates
Restore --out parameter for backward compatibility
--out flag as a deprecated alias for --output/-o to maintain compatibility with existing GitHub Actions and CI/CD pipelines--output instead--output and --out are provided, --output takes precedenceRestore --json parameter for backward compatibility
--json flag as a deprecated alias for --output-format json to maintain compatibility with existing GitHub Actions and CI/CD pipelines--output-format instead--json is provided, it sets the output format to JSONMissing using statement (161766f)
using System; directive in Program.csWorkflow security hardening (#975, 39b8986)
permissions: contents: read to permissions: read-allPin GitHub Actions versions (1145c82)
Enable NuGet package locking (#972, fad44df)
packages.lock.json files for both main and test projectsRestorePackagesWithLockFile in Directory.Build.propsUpdate NuGet dependencies (#973, e930da1)
NuGet.ProjectModel from 6.9.1 to 6.14.0NuGet.Protocol from 6.9.1 to 6.14.0🚀 CycloneDX .NET v5.5.0 Release Notes
.csproj file locations in .slnf files — paths are now correctly resolved relative to the .sln file. [#967](#967) (thanks [@uo-uhbc](https://github.com/uo-uhbc))IsTestProject detection to use the correct XML namespace when parsing project files. [#938](#938) (thanks [@benavidezb](https://github.com/benavidezb))[v5.4.0 → v5.5.0](v5.4.0...v5.5.0)
Add support for solution filter file ( #853 ) by @michha in #920
🚀 CycloneDX .NET v5.3.2 Release Notes
Addressed the performance regression introduced in v5.3.1 that caused longer execution times. The CLI now attempts to locate the project.assets.json at its default location before falling back to invoking dotnet msbuild, restoring execution speed for projects that use the default /obj directory. #960
⚠️ The previously used --json flag is now deprecated and will be removed in a future release. Use --format json instead for the same behavior—with mor…
We’re aware of a performance problems introduced in v5.3.1 that can significantly increase execution time, most likely when scanning large .sln files. SBOM generation may take noticeably longer compared to previous versions. We're investigating the root cause and working on improvements for a future release.
✅ This has been fixed in v5.3.2
Analyzer Support for MSBuild-based project.assets.json Resolution – The CLI now supports analysis of MSBuild-based projects by resolving project.assets.json using MSBuild context. This improves compatibility with SDK-style projects. #952.
New --output-format Parameter (Replaces --json) – A new --output-format parameter has been added, allowing explicit selection of output format (json, xml, unsafejson, or auto).
⚠️ The previously used --json flag is now deprecated and will be removed in a future release. Use --format json instead for the same behavior—with more flexibility.
(https://github.com/mtsfoni) in #953.
CycloneDX Format v1.6.1 – BOMs are now generated using the CycloneDX 1.6.1 specification, ensuring compatibility with the latest schema and supporting new fields/features defined in the spec.
📜 Full Changelog: v5.2.0 → v5.3.1
Nothing published for this version
Fix Error with Uppercase Characters in Version Strings by @JohnHunhoff in #902
Full Changelog: v5.1.1...v5.2.0
Fixes a null reference exception that can occur in v5.1.0
Fixes a null reference exception that can occur in v5.1.0
Full Changelog: v5.1.0...v5.1.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →