NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3093 most downloaded on PyPI
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Last release 5 days ago
29 Sep 2026
Release timing varies
gaps range from 2 weeks to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
8 years old
124 releases · first in 2018
Fix typo in help page (#552) (`19bf41a`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.11.0...v3.11.1
One column per quarter.
Deprecated CLI command cyclonedx-bom prints deprecation warning on STDERR before execution (#489) (`2009236`)
cyclonedx-bom prints deprecation warning on STDERR before execution (#489) (2009236)mypy by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/478cyclonedx-bom prints deprecation warning on STDERR before execution by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python/pull/489Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.10.1...v3.11.0
PURL for PyPI packages from 'conda list' have the correct format now (#471) (`1573064`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.10.0...v3.10.1
Add support for poetry lock format v2.0 (#469) (`0b1e07f`)
Parsers can outbut more debug messages (#466) (`9eedb4f`)
Error- and debug-output is send to STDERR, instead of STDOUT (#465) (`f543b69`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v3.7.4...v3.8.0
Ignore broken licenses in env parser (#463) (`3118acd`)
Adjust dependency pip-requirements-parser to a working version (#450) (`6101986`)
Add a missing space in the help pages pathto -> path to (#443) (`bc5fe57`)
EnvironmentParser: Reduced crashes if no Classifiers are found (#441) (`67f56e7`)
Pass purl-bom-ref to EnvironmentParser (#432) (`7cfefeb`)
EnvironmentParser: Remove code break when classifier parsing in py>=3.8 (#431) (`4ab075e`)
CI release pipeline (`99ccdc6`)
99ccdc6)CI release pipeline (`6515071`)
6515071)Properly declare licenses from environment (#417) (`25f9e29`)
Enable dependency cyclonedx-python-lib@^3 (#418) (`05cd51e`)
Optionally force bom_ref to be purl rather that the default random UUID format - thanks @RodneyRichardson (`9659d08`)
bom_ref to be purl rather that the default random UUID format - thanks @RodneyRichardson (9659d08)Update purl to match specification when ingesting packages from Conda - thanks to @RodneyRichardson (`072c8f1`)
072c8f1)Add Conda MD5 hash to Component.hashes, if available - thanks @RodneyRichardson (`772c517`)
772c517)Add actively used (transitive) dependencies (#363) (`1f45ad9`)
Cli default file for json format (`8747620`)
8747620)Make module callable (`5b3d8d7`)
2bac83a)5b3d8d7)conda-parser: Version recognition for strings (#332) (`65246dd`)
Add pip-requirements-parser and update virtualenv to latest version (`73b2182`)
9e9021d)Bump to latest cyclonedx-python-lib (`5902fbf`)
Added marker and classifiers to denote this as typed
(#313,
f317353)
Bump to latest cyclonedx-python-lib
(5902fbf)
BREAKING CHANGE: Default Schema Version has been replaced by notion of LATEST supported Schema Version
Update to latest RC of cyclonedx-python-lib
(6c8b517)
Update to latest RC of cyclonedx-python-lib
(bc8ee6b)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Docker image release checkout ref w/o tags (#309) (`5d8b1e1`)
Properly support reading from stdin (#307) (`23f31a0`)
Bump dependencies to get latest cyclonedx-python-lib (`87c3fe7`)
cyclonedx-python-lib (87c3fe7)cyclonedx-python-lib
(87c3fe7)Add support for CycloneDX 1.4 specification (#294) (`7bb6d32`)
Nothing published for this version
Nothing published for this version
Revert to previous process for building Docker image as PyPi index update is too slow to pull straight away after publish (`67bb738`)
67bb738)Corrected docker image build process to not rely on dist folder which is cleaned up by python-semantic-release (`6c65c11`)
dist folder which is cleaned up by python-semantic-release (6c65c11)Re-enable build and publish of Docker Image (#263) (`478360d`)
Support for Python 3.10 (#261) (`f4f9ffe`)
Add static code analysis, better typing and bump cyclonedx-python-lib to 0.11 (`d5d9f56`)
d5d9f56)d5d9f56)If no input file is supplied and no input is provided on STDIN, we will now try to automatically locate (in the current working directory) a manifest
93f9e59)Corrected documentation after deprecation of -rf, -pf, --poetry-file, --requirements-file and --pip-file (`4c4c8d8`)
-rf, -pf, --poetry-file, --requirements-file and --pip-file (4c4c8d8)-rf, -pf, --poetry-file, --requirements-file
and --pip-file
(4c4c8d8)Add conda support (bump cyclonedx-python-lib to ^0.10.0) (`cb24275`)
Encoding issues on Windows (bump cyclonedx-python-lib to ^0.10.1)
(fe5df36)
Encoding issues on Windows (bump cyclonedx-python-lib to ^0.10.2)
(da6772b)
cb24275)Bump to cyclonedx-python-lib to resolve issue #244 (`ebea3ef`)
ebea3ef)ebea3ef)Add license information in CycloneDX BOM when using Environment as the source (`5d1f9a7`)
5d1f9a7)Update to latest stable cyclonedx-python-lib (`6145bd5`)
6145bd5)Add support for generating SBOM from poetry.lock files (`bb4ac0f`)
bb4ac0f)bb4ac0f)Handle requirements.txt which contain dependencies without a version statement and warn that they cannot be included in the resulting CycloneDX BOM (`
requirements.txt which contain dependencies without a version statement and warn that they cannot be included in the resulting CycloneDX BOM (e637e56)Error message when requirements.txt file is non-existent updated (`3bbc071`)
requirements.txt file is non-existent updated (3bbc071)requirements.txt file is non-existent updated
(3bbc071)Default to "requirements.txt" in current directory when "-r" flag is supplied but not "-rf" flag is supplied (`bb7e30a`)
bb7e30a)bb7e30a)### Fix * Release GH action (`148421b`)
148421b)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
- Initial Release
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →