NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3093 most downloaded on PyPI
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Last release 5 days ago
29 Sep 2026
Release timing varies
gaps range from 2 weeks to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
8 years old
124 releases · first in 2018
deps : Support chardet v7 ( #1110 , e1e1040 )
chardet v7 by @tamird in #1110Full Changelog: v7.4.0...v7.5.0
One column per quarter.
Respect env var SOURCE_DATE_EPOCH when generating reproducible output ( #1084 , 51813c7 )
SOURCE_DATE_EPOCH when generating reproducible output by @Yusuf-Gadelrab in #1084Full Changelog: v7.3.1...v7.4.0
Improve error message for non-PEP 621 pyproject.toml ( #1080 , 6715bd9 )
cyclonedx-py environment help page add -S by @jkowalleck in #1033Full Changelog: v7.3.0...v7.3.1
Add -S flag to skip *.pth evaluation during environment analysis ( #1032 , 55c15d7 )
*.pth evaluation during environment analysis by @jkowalleck in #1032Full Changelog: v7.2.2...v7.3.0
Modernize RTF setup ( #1002 , 206c17e )
Full Changelog: v7.2.1...v7.2.2
Basic support for CycloneDX 1.7 ( #984 , 6477a3f )
Maintenance release.
Full Changelog: v7.2.0...v7.2.1
Support Python 3.14 ( #982 , ef36abe )
5f38d75)Full Changelog: v7.1.0...v7.2.0
Support runtime-dependency cyclonedx-python-lib v11 ( #938 , 7818754 )
1e6574f)cyclonedx-python-lib v11 by @jkowalleck in #938Full Changelog: v7.0.0...v7.1.0
Detailed Changes : v7.0.0-alpha.1...v7.0.1-alpha.2
v7.0.1-alpha.2 Pre-release
Pre-release
Compare
Remove deprecated CLI switches --schema-version and --outfile , use --spec-version and --output-file instead ( #892 , 2be98e5 )
environment --PEP-639 (#928, 6b81028)
environment --PEP-639 was removed.--schema-version and --outfile, use --spec-version and --output-file instead (#892, 2be98e5)environment --PEP-639 by @jkowalleck in #928--schema-version and --outfile, use --spec-version and --output-file instead by @virgo-o in #892Full Changelog: v6.1.3...v7.0.0
Detailed Changes : v6.1.3...v7.0.0-alpha.1
v7.0.0-alpha.1 Pre-release
Pre-release
Compare
License file detection according to PEP621 ( #929 , 28dcbf7 )
Full Changelog: v6.1.2...v6.1.3
Make pep621 license detections type-aware (#920, `0c9aeac`)
Formatting and reorder of code style instructions. (15ac2cd)
License file *.rst are NOT type text - they are binary (#911, 168f81d)
*.rst are NOT type text - they are binary by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/911Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v6.1.1...v6.1.2
Detailed Changes: v6.1.0...v6.1.1
e3c168b)Signed-off-by: Jan Kowalleck jan.kowalleck@gmail.com
Detailed Changes: v6.1.0...v6.1.1
Fix default value for --spec-version (`2f2982b`)
--spec-version (2f2982b)Signed-off-by: Jan Kowalleck jan.kowalleck@gmail.com
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v6.0.0...v6.1.0
Detailed Changes: v6.1.0-alpha.1...v6.1.0-rc.1
Fix default value for --spec-version (`2f2982b`)
--spec-version (2f2982b)Signed-off-by: Jan Kowalleck jan.kowalleck@gmail.com
As per OWASP's Docker Security Cheat Sheet, it is recommended to set a user instead of running the container as root.
bash virgo@lenovo:~$ docker ps -a CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES ee568549229f cyclonedx-py:latest "/bin/bash" About a minute ago Up About a minute nifty_swirles virgo@lenovo:~$ docker exec -it ee568549229f sh -c "id" uid=1000(cyclonedx) gid=1000(cyclonedx) groups=1000(cyclonedx)
:arrow_up: Now the container is running as a standard user.
Signed-off-by: virgo-o virgoj@protonmail.com
Detailed Changes: v6.0.0...v6.1.0-alpha.1
spec-version defaults to CycloneDX 1.6
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v5.5.0...v6.0.0
feat: support runtime-dependency packaging ^25
packaging ^25 (#882)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (4fa5a35)
feat: deprecate CLI switch --outfile; use new --output-file instead
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (3c86517)
uv (#858)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (efd45b1)
uvSigned-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (07d9bcc)
cyclonedx-python-lib ^10 (#880)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (545dde0)
--outfile; use new --output-file instead (#875)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (fb30ee0)
--schema-version; use new --spec-version instead (#871)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (bbae05f)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (4837c99)
feat: add support for cyclonedx-python-lib>=9.0 <10
cyclonedx-python-lib>=9.0 <10 (#854)cyclonedx-python-lib>=9.0<10 by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/854Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v5.2.0...v5.3.0
docs: showcase uv as installation option
uv as installation option (#847)environment got aliases env, venv (#850)uv as installation option by @lightningRalf in https://github.com/CycloneDX/cyclonedx-python/pull/847environment got aliases env, venv by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/850Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v5.1.2...v5.2.0
fix(poetry): properly handle multi-declaration (optional) dependencies (#842) fixes #840
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v5.1.1...v5.1.2
docs: fix headline structure in readme
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v5.1.0...v5.1.1
tests: requirements with url and git node id by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/817
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v5.0.0...v5.1.0
Emitted metadata tools are up to non-deprecated CycloneDX specification.
cyclonedx-py, was cyclonedx-bom.cdx:poetry (see previous release 4.6.0 for official replacements).
cdx:poetry:source:package:referencecdx:poetry:package:source:resolved_referencecdx:poetry:package:source:vcs:requested_revisioncdx:poetry:package:source:vcs:commit_idThe mentioned changes are considered "breaking" for processes that relied on the respective data structures. Migration paths are self-explanatory.
cyclonedx-python-lib>=8.0.0,<9 now, was >=7.3.0,<8.0.0,!=7.3.1.Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.6.1...v5.0.0
cyclonedx-py, was cyclonedx-bom. * Emitted metadata tools are up
to non-deprecated CycloneDX specification. * No longer emit deprecated or undocumented properties
in namespace
cdx:poetry
(see previous release 4.6.0 for official replacements). - cdx:poetry:source:package:reference -
cdx:poetry:package:source:resolved_reference -
cdx:poetry:package:source:vcs:requested_revision - cdx:poetry:package:source:vcs:commit_idThe mentioned changes are considered "breaking" for processes that relied on the respective data structures. Migration paths are self-explanatory.
cyclonedx-python-lib>=8.0.0,<9 now, was >=7.3.0,<8.0.0,!=7.3.1.Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> Signed-off-by: semantic-release <semantic-release@bot.local> Co-authored-by: semantic-release <
fixes #794
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: semantic-release <semantic-release@bot.local>
Co-authored-by: semantic-release <semantic-release@bot.local> (721f12d)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (2ae46ff)
fixes #804
Signed-off-by: Steve (Gadget) Barnes <gadgetsteve@hotmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Co-authored-by: Jan Kowalleck <jan.kowalleck@gmail.com> (9e8a5d7)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c7b5b1a)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.6.0...v4.6.1
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`07b5e83`)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (07b5e83)
the deprecated properties are still used, so no breaking changes exist.
usage docs (#788)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (a1354e5)
cdx:python:package:source:vcs:... (#790)populate the newly added/fixed CycloneDX properties
cdx:python:package:source:vcs:... in accordance with
<https://github.com/CycloneDX/cyclonedx-property-taxonomy/pull/96> and
<https://github.com/CycloneDX/cyclonedx-property-taxonomy/pull/98>.
the deprecated properties are still used, so no breaking changes exist.
fixes #789
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (b08e1bb)
usage docs by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/788cdx:python:package:source:vcs:... by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/790Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.5.1...v4.6.0
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`9f9fa9e`)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (9f9fa9e)
utilizes flake8 plugin <https://pypi.org/project/flake8-copyright-validator/> to assert the correct headers
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (dddcb5d)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.5.0...v4.5.1
chore: shield_ossf-best-practices subbary
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (1a1ad60)
supersedes #625 supersedes #624
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (1222201)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (3d02d6a)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (5717803)
From python environments, gather additional declared license information according to PEP 639 (improving license clarity with better package metadata).
New CLI switches for cyclonedx environment:
--PEP-639: Enable license gathering according to PEP 639 (improving
license clarity with better package metadata).
The behavior may change during the draft development of the PEP.--gather-license-texts: Enable license text gathering.In current state of implementation, --gather-license-texts has effect
only if --PEP-639 is also given.
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (e9cc805)
pypi (#754)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (cba521e)
extred -> extref (#753)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (a178d2e)
Signed-off-by: Jan Kowalleck <jan.kowalleck@owasp.org> (f13311b)
Signed-off-by: Jan Kowalleck <jan.kowalleck@owasp.org> (c4b15d8)
Signed-off-by: Jan Kowalleck <jan.kowalleck@owasp.org> (58199a5)
extred -> extref by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/753pypi by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/754Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.4.3...v4.5.0
fix: do not use cyclonedx-lib==7.3.1
cyclonedx-lib==7.3.1 (#729)add regression test for #727 fixes #727
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (aa715c0)
cyclonedx-lib==7.3.1 by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/729Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.4.2...v4.4.3
fix: release lates container image
lates container image (#726)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (0155450)
fix: release lates container image
lates container image (#725)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (8ba9d0b)
chore: semantic-release git commit/sign valid email address
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (692b8ea)
Tee container image version of the app is also available on GitHubContainerRegistry: <https://github.com/orgs/CycloneDX/packages/container/package/cyclonedx-python>
Signed-off-by: jxdv <virgoj@protonmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: semantic-release <semantic-release@bot.local>
Co-authored-by: jxdv <virgoj@protonmail.com>
Co-authored-by: semantic-release <semantic-release@bot.local> (8c18484)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.3.0...v4.4.0
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`c48096b`)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c48096b)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`f1c6136`)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (f1c6136)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`44608d0`)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (44608d0)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (3c9428f)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (fba87d9)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (43a3dad)
chore: semantic-release git commit/sign valid email address
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (692b8ea)
Closes #695. (87218e6)
fixes #718
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: jxdv <virgoj@protonmail.com> (d47640b)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (bfce1d1)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (6644556)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (3d6a7ce)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (aefd5a6)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (f8ff29e)
Merge branch 'main' into ghcr-publish (46f7ada)
Merge branch 'main' into ghcr-publish (1cb7a5f)
docs
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: jxdv <virgoj@protonmail.com> (b7975ea)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: jxdv <virgoj@protonmail.com> (b8b9409)
Signed-off-by: jxdv <virgoj@protonmail.com> (da572de)
Signed-off-by: jxdv <virgoj@protonmail.com> (25d2449)
Signed-off-by: jxdv <virgoj@protonmail.com> (2e9d2fc)
Signed-off-by: jxdv <virgoj@protonmail.com> (9508cd0)
feat: improve declared licenses detection
fixes #718
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (b0ae453)
feat: support CycloneDX 1.6 output
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (639b35a)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.1.6...v4.2.0
fix: more resilent PEP610 parsing
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (93f0184)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.1.5...v4.1.6
fix: docs for default of CLI switch --mc-type
--mc-type (#710)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (a218b40)
--mc-type by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/710Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.1.4...v4.1.5
chore(deps-dev): Update autopep8 requirement from 2.0.4 to 2.1.0
Updates the requirements on autopep8 to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (59f07c1)
Updates the requirements on flake8-logging to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (dfc63b6)
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (7ae2145)
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (bd3f232)
Updates the requirements on coverage to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (8181ce9)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (8ade6e1)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.1.3...v4.1.4
chore(deps): Bump python-semantic-release/python-semantic-release
Bumps python-semantic-release/python-semantic-release from 8.5.1 to 9.1.1.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (f27170e)
Bumps actions/setup-python from 4 to 5.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (e661fb2)
Updates the requirements on bandit to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (40f16e0)
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (16efe0b)
Updates the requirements on mypy to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (de3be95)
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (33d2b9b)
Updates the requirements on ddt to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (743324a)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (dc81c35)
environment use cases and examples (#690)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (0d38c7b)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (ec7ab3e)
environment use cases and examples by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/690Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.1.2...v4.1.3
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`dba63b8`)
Mainenance release.
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (dba63b8)
Updates the requirements on coverage to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (dadc9b5)
Bumps Gr1N/setup-poetry from 8 to 9.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (5ee8bb2)
Updates the requirements on flake8-quotes to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (4da9c9e)
Updates the requirements on flake8-bugbear to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (14a8ec0)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.1.1...v4.1.2
docs: improve example for programmatic call of CLI
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (2ac3f21)
ALL names of package extras are normalized, according to spec <https://packaging.python.org/en/latest/specifications/name-normalization/#name-normalization>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (4d550ad)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.1.0...v4.1.1
feat: support poetry multi-constraint dependencies
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (50d2a4b)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (2fd3faf)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (491e875)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.0.0...v4.1.0
BC: Removed deprecated shell script cyclonedx-bom; use cyclonedx-py instead
See also the migration guide in the docs: https://cyclonedx-bom-tool.readthedocs.io/en/v4.0.0/upgrading.html
cyclonedx-bom; use cyclonedx-py instead--short-PURLs)--no-validate)pyproject provided)diff-friendly and not just one long line of textFull Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.11.7...v4.0.0
Full Changelog since v4.0.0-RC6: https://github.com/CycloneDX/cyclonedx-python/compare/v4.0.0-rc.6...v4.0.0
fix: package name normalization - https://github.com/CycloneDX/cyclonedx-python/pull/652
changes since RC5:
Changelog: see https://github.com/CycloneDX/cyclonedx-python/pull/605
Docs: see https://cyclonedx-bom-tool.readthedocs.io/en/dev-4.0.0/
Install via: pip install cyclonedx-bom==4.0.0rc6
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.0.0-rc.5...v4.0.0-rc.6
feat: strip authentication secrets from private index/download URL - https://github.com/CycloneDX/cyclonedx-python/issues/646
changes since RC4:
Changelog: see https://github.com/CycloneDX/cyclonedx-python/pull/605
Docs: see https://cyclonedx-bom-tool.readthedocs.io/en/dev-4.0.0/
Install via: pip install cyclonedx-bom==4.0.0rc5
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v4.0.0-rc.4...v4.0.0-rc.5
No changes since RC3. Fixed docker image release process.
No changes since RC3. Fixed docker image release process.
Changelog: see https://github.com/CycloneDX/cyclonedx-python/pull/605
Docs: see https://cyclonedx-bom-tool.readthedocs.io/en/dev-4.0.0/
Install via: pip install cyclonedx-bom==4.0.0rc4
No changes since RC1 Try to fix docker image release process.
No changes since RC1 Try to fix docker image release process.
Changelog: see https://github.com/CycloneDX/cyclonedx-python/pull/605
Docs: see https://cyclonedx-bom-tool.readthedocs.io/en/dev-4.0.0/
Install via: pip install cyclonedx-bom==4.0.0rc2
BREAKING CHANGE: remove deprecated cyclonedx-bom command #488 by @madpah in https://github.com/CycloneDX/cyclonedx-python/pull/526
Changelog: see https://github.com/CycloneDX/cyclonedx-python/pull/605
Docs: see https://cyclonedx-bom-tool.readthedocs.io/en/dev-4.0.0/
Install via: pip install cyclonedx-bom==4.0.0rc1
cyclonedx-python-lib to latest RC of 4.0.x by @madpah in https://github.com/CycloneDX/cyclonedx-python/pull/521cyclonedx-bom command #488 by @madpah in https://github.com/CycloneDX/cyclonedx-python/pull/526cyclonedx-python-lib 4.0.0 by @madpah in https://github.com/CycloneDX/cyclonedx-python/pull/536cyclonedx-python-lib@^4 -> @^4.2 by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/578python-semantic-release@8 by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/589Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.11.7...v4.0.0-rc.1
Toml-compatible fingers-crossed handling for failed input data decoding (#613) (`fb3d7bf`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.11.6...v3.11.7
Added a fingers-crossed handling for failed input data decoding (#612) (`be55902`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.11.5...v3.11.6
Custom input encoding (#601) (`363934c`)
Input file encoding fallback (`0bc7296`)
0bc7296)Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.11.3...v3.11.4
Input file encoding (#596) (`a9dda4b`)
bd4f48e)ccac31e)ShellSession in README (411cf3d)Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.11.2...v3.11.3
Referenced branch main, instead of master (#562) (`830d15c`)
Your coding agent can read these notes before it upgrades. Set up the MCP server →