NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #572 most downloaded on PyPI
Python library for CycloneDX
Last release 1 months ago
13 Aug 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
5 years old
160 releases · first in 2021
One column per quarter.
Add isExternal property to Component for CycloneDX v1.7 ( #959 , 6993dea )
Full Changelog: v11.11.2...v11.12.0
Encode paths when loading XML schemas ( #1028 , 17a0136 )
Full Changelog: v11.11.1...v11.11.2
Comparablepackageurl includes name ( #1022 , d718ac2 )
name by @arpitjain099 in #1022Full Changelog: v11.11.0...v11.11.1
Protocolpropertiestype enum case 5g-aka for CycloneDX 1.7 ( #1004 , bc97e1c )
cryptoprimitive enum cases for CycloneDX 1.7 (#1002, 788ced1)
protocolpropertiestype enum cases for CycloneDX 1.7 (#1003, f9223d8)
CryptoPrimitive enum cases for CycloneDX 1.7 by @jkowalleck in #1002ProtocolPropertiesType enum cases for CycloneDX 1.7 by @jkowalleck in #10035g-aka for CycloneDX 1.7 by @jkowalleck in #1004contrib.bom.utils by @jkowalleck in #1000Full Changelog: v11.10.0...v11.11.0
Lossless flattening of dependency graph during JSON serialization ( #993 , d0e10ca )
Lossless flattening of dependency graph during JSON serialization (#993, d0e10ca)
Typing in contrib.bom.utils.BomDependencyGraphFlatMerger (#998, 988a937)
Add contrib.bom.utils.BomDependencyGraphFlatMerger (#997, 78b8d8b)
Move output.BomRefDiscriminator to contrib.bom.utils.BomRefDiscriminator (#995, 3bb87aa)
output.BomRefDiscriminator to contrib.bom.utils.BomRefDiscriminator by @jkowalleck in #995contrib.bom.utils.BomRefDiscriminator by @jkowalleck in #996contrib.bom.utils.BomDependencyGraphFlatMerger by @jkowalleck in #997contrib.bom.utils.BomDependencyGraphFlatMerger by @jkowalleck in #998contrib.bom.utils.BomDependencyGraphFlatMerger._flatten_merge by @jkowalleck in #999Full Changelog: v11.9.0...v11.10.0
Add support for license expression details ( #908 , b502381 )
Full Changelog: v11.8.0...v11.9.0
Update CDX summary ( #951 , 752b162 )
Full Changelog: v11.7.0...v11.8.0
Detailed Changes : v11.7.0...v11.7.1-alpha.2
v11.7.1-alpha.2 Pre-release
Pre-release
Compare
v11.7.1-alpha.1 (2026-05-04) test release during #969 Full Changelog : v11.7.0...v11.7.1-alpha.1
v11.7.1-alpha.1 Pre-release
Pre-release
Compare
Make schema deprecation warnings handle-able (#945, `71edacf`)
Add properties for licenses according to CycloneDX 1.5 (#947, 375d209)
Make schema deprecation warnings handle-able (#945, 71edacf)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v11.6.0...v11.7.0
Detailed Changes : v11.7.0-rc.3...v11.7.0-rc.4
test release during https://github.com/CycloneDX/cyclonedx-python-lib/pull/961
test release during https://github.com/CycloneDX/cyclonedx-python-lib/pull/961
Detailed Changes: v11.7.0-rc.2...v11.7.0-rc.3
test release during https://github.com/CycloneDX/cyclonedx-python-lib/pull/961
test release during https://github.com/CycloneDX/cyclonedx-python-lib/pull/961
Detailed Changes: v11.7.0-rc.1...v11.7.0-rc.2
test release during https://github.com/CycloneDX/cyclonedx-python-lib/pull/961
test release during https://github.com/CycloneDX/cyclonedx-python-lib/pull/961
Detailed Changes: v11.7.0...v11.7.0-rc.1
model.bom.Bom.get_vulnerabilities_for_bom_ref()
15a9023)
contrib.model.bom.Bom.get_component_by_purl()model.bom.Bom.get_urn_uuid()model.bom.Bom.has_component()model.bom.Bom.get_vulnerabilities_for_bom_ref()model.bom.Bom.has_vulnerabilities()model.bom.Bom.urn()builder.this.this_component() -> contrib.this.builders.this_component()builder.this.this_tool() -> contrib.this.builders.this_tool()exception.factory.* -> contrib.license.exceptions.*factory.license.LicenseFactory -> contrib.license.factories.LicenseFactorymodel.HashType.from_hashlib_alg() -> contrib.hash.factories.HashTypeFactory.from_hashlib_alg()model.HashType.from_composite_str() -> contrib.hash.factories.HashTypeFactory.from_composite_str()model.component.Component.for_file() -> contrib.component.builders.ComponentBuilder.make_for_file()model.vulnerability.VulnerabilitySeverity.get_from_cvss_scores() -> contrib.vulnerability.cvss.vs_from_cvss_scores()Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v11.5.0...v11.6.0
Add support for DistributionConstraints in BOM metadata (#906, `70adb7c`)
Add support for DistributionConstraints in BOM metadata (#906, 70adb7c)
Add support for properties in external references (#907, 73e7c1a)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v11.4.0...v11.5.0
Add support for CycloneDX 1.7 (basics) (#902, `f35b9ee`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v11.3.0...v11.4.0
Implement __lt__ for models still missing it (#899, `bebda4f`)
ComponentEvidence.identity by @qkaiser in https://github.com/CycloneDX/cyclonedx-python-lib/pull/900__lt__ for models still missing it by @qkaiser in https://github.com/CycloneDX/cyclonedx-python-lib/pull/899Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v11.2.0...v11.3.0
Add Changelog to project urls (`d8a24b7`)
d8a24b7)Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v11.1.0...v11.2.0
Update CDX spec links (#858, `ba0b5c0`)
Shorten lines (5621705)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v11.0.0...v11.1.0
Ignore unknown properties when deserializing (#853, `4842828`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.5.0...v11.0.0
Use only nonGPL dependencies (#854, `9c14ee6`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.4.1...v10.5.0
Add runtime dependnecy typing_extensions>=4.6; python_version<"3.13" (#845, `95b560a`)
Add runtime dependnecy typing_extensions>=4.6; python_version<"3.13" (#845, 95b560a)
Added runtime dependnecy referencing>=0.28.4" (#846, 4d01e87)
typing_extensions>=4.6; python_version<"3.13" by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/845referencing>=0.28.4" by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/846Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.4.0...v10.4.1
Issue DeprecationWarnings for deprecated properties properly (#838, `34a11aa`)
Issue DeprecationWarnings for deprecated properties properly (#838, 34a11aa)
Removed meaningless pattern checks for CycloneDX 1.2 JSON schema (#843, 6e8083a)
DeprecationWarnings for deprecated properties properly by @KAWAHARA-souta in https://github.com/CycloneDX/cyclonedx-python-lib/pull/838Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.3.0...v10.4.0
Instructions for code style (`160810f`)
160810f)Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.2.0...v10.3.0
vulnerabilityscoresource.get_from_vector() for CVSS_V3_1 and CVSS_V4 (#824, `a97ccd4`)
VulnerabilityScoreSource.get_from_vector() for CVSS_V3_1 and CVSS_V4 by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/824Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.1.0...v10.2.0
Pulled SPDX license IDs v1.0-3.26.0 (#823, `41b2d25`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.0.2...v10.1.0
model.bommetadata.component setter typehint (#817, `bfe889a`)
model.BomMetaData.component setter typehint by @dependabot in https://github.com/CycloneDX/cyclonedx-python-lib/pull/817Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.0.1...v10.0.2
Add missing comparator for VulnerabilityAnalysis (#812, `0df2982`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v10.0.0...v10.0.1
Drop support for Python <3.9 (#809, `8b2a07d`)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v9.1.0...v10.0.0
maintenance release to see https://github.com/CycloneDX/cyclonedx-python-lib/issues/793 in action
maintenance release to see https://github.com/CycloneDX/cyclonedx-python-lib/issues/793 in action
feat: model.VulnerabilityAnalysis properties for issued/updated datetime
model.VulnerabilityAnalysis properties for issued/updated datetime (#794)model.VulnerabilityAnalysis (#795)model.VulnerabilityAnalysis by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/795Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v9.0.2...v9.1.0
# v9.0.2 (2025-02-26) maintenance release ---- Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v9.0.0...v9.0.2
maintenance release
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v9.0.0...v9.0.2
BomRef affects comparison/hashing (#754 & #780) This is only a breaking change if you relied on ordering of elements.
spdx.is_compund_expression -> spdx.is_expression (#779)py-serializable >=2 <3, was >=1.1.1 <2 (#775)cyclonedx.model.crypto.ProtocolProperties.crypto_refs by @indiVar0508 in https://github.com/CycloneDX/cyclonedx-python-lib/pull/767crypto_refs by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/778spdx.is_compund_expression -> spdx.is_expression by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/779spdx.is_expression() by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/782Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v9.0.0-rc.1...v9.0.1-rc.1
Fix: model.vulnerability.VulnerabilityReference's properties are all mandatory (#790 via #792)
model.vulnerability.VulnerabilityReference's properties are all mandatory (#790 via #792)spdx.is_compund_expression -> spdx.is_expression (#779)BomRef affects comparison/hashing (#754 & #780)py-serializable >=2 <3, was >=1.1.1 <2 (#775)Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.9.0...v9.0.0
see https://github.com/CycloneDX/cyclonedx-python-lib/pull/777
see https://github.com/CycloneDX/cyclonedx-python-lib/pull/777
py-serializable >=2 <3, was >=1.1.1 <2 (#775)py-serializable==^1.1.1 -> ^2.0.0 by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/775Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.7.0...v9.0.0-rc.1
cyclonedx.model.vulnerability.VulnerabilityAnalysis
NoPropertiesProvidedException for optional parameters (#786)the following classes' init no longer raise NoPropertiesProvidedException:
cyclonedx.model.IdentifiableActioncyclonedx.model.component.Commitcyclonedx.model.component.ComponentEvidencecyclonedx.model.component.Diffcyclonedx.model.component.Pedigreecyclonedx.model.issue.IssueTypeSourcecyclonedx.model.vulnerability.VulnerabilityAnalysiscyclonedx.model.vulnerability.VulnerabilityCreditscyclonedx.model.vulnerability.VulnerabilityRatingcyclonedx.model.vulnerability.VulnerabilitySourceNoPropertiesProvidedException for optional parameters by @indiVar0508 in https://github.com/CycloneDX/cyclonedx-python-lib/pull/786Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.8.0...v8.9.0
feat: add cyclonedx.model.crypto.ProtocolProperties.crypto_refs
cyclonedx.model.crypto.ProtocolProperties.crypto_refs (#767)cyclonedx.model.crypto.ProtocolProperties.crypto_refs by @indiVar0508 in https://github.com/CycloneDX/cyclonedx-python-lib/pull/767crypto_refs by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/778Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.7.0...v8.8.0
feat: allow empty OrganizationalContact object
OrganizationalContact object (#772)OrganizationalContact object by @Churro in https://github.com/CycloneDX/cyclonedx-python-lib/pull/772Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.6.0...v8.7.0
feat: expand the capabilities of models.definition.Standard
models.definition.Standard (#713)OrganizationalEntity object (#768)OrganizationalEntity object by @Churro in https://github.com/CycloneDX/cyclonedx-python-lib/pull/768Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.5.1...v8.6.0
feat: couple classes and their serializes (#757) Deprecates .serialization.BomRefHelper and .serialization.LicenseRepositoryHelper. (stealth-release o…
.serialization.BomRefHelper and .serialization.LicenseRepositoryHelper.
(stealth-release of this feature, as it is almost only used internally)Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.5.0...v8.5.1
docs: remove invalid docsting note about auto-assigned bom-ref values (#733) (`5aa5787`)
bom-ref values (#733) (5aa5787)bom-ref values by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/733Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.4.0...v8.5.0
feat: add factory method XsUri.make_bom_link()
XsUri.make_bom_link() (#728)Definitions docstring (#731)bom_ref_from_str by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/727Definitions docstring by @hakandilek in https://github.com/CycloneDX/cyclonedx-python-lib/pull/731XsUri.make_bom_link() by @saquibsaifee in https://github.com/CycloneDX/cyclonedx-python-lib/pull/728Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.3.0...v8.4.0
feat: add basic support for Definitions
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.2.1...v8.3.0
fix: encode quotation mark in URL
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.2.0...v8.2.1
feat: Add Python 3.13 support by @gruebel in https://github.com/CycloneDX/cyclonedx-python-lib/pull/718
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.1.0...v8.2.0
docs: fix code examples regarding outputting
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.0.0...v8.1.0
Property cyclonedx.mode.vulnerability.Vulnerability.tools is of type cyclonedx.model.tool.ToolRepository now, was SortedSet[cyclonedx.model.Tool]. The…
cyclonedx.mode.ThisTool, utilize cyclonedx.builder.this.this_tool() instead.cyclonedx.model.Tool to cyclonedx.model.tool.Tool.cyclonedx.mode.bom.BomMetaData.tools is of type cyclonedx.model.tool.ToolRepository now, was SortedSet[cyclonedx.model.Tool].cyclonedx.mode.vulnerability.Vulnerability.tools is of type cyclonedx.model.tool.ToolRepository now, was SortedSet[cyclonedx.model.Tool].cyclonedx.model.license.LicenseExpression() accepts optional argument acknowledgement only as key-word argument, no longer as positional argument.cyclonedx.model.bom.BomMetaData also accepts an instance of cyclonedx.model.tool.ToolRepository for argument tools.cyclonedx.model.bom.BomMetaData no longer adds this very library as a tool.my-bom.metadata.tools.components.add(cyclonedx.builder.this.this_component()).Enabled Metadata Tools representation and serialization in accordance with CycloneDX 1.5
cyclonedx.model.tool.ToolRepository.cyclonedx.builder.this.this_component() -- representation of this very python library as a Component.cyclonedx.builder.this.this_tool() -- representation of this very python library as a Tool.cyclonedx.model.tool.Tool.from_component().py-serializable>=1.1.1,<2, was >=1.1.0,<2.see https://cyclonedx-python-library.readthedocs.io/en/v8.0.0/upgrading.html
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.6.2...v8.0.0
Property cyclonedx.mode.vulnerability.Vulnerability.tools is of type cyclonedx.model.tool.ToolRepository now, was SortedSet[cyclonedx.model.Tool]. The…
ToolsRepository -> ToolRepository (#687)ToolRepository serialization will properly deduplicate migrated itemsToolsRepository -> ToolRepository by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/687Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v8.0.0-rc.1...v8.0.0-rc.2
cyclonedx.mode.ThisTool, utilize cyclonedx.builder.this.this_tool() instead.cyclonedx.model.Tool to cyclonedx.model.tool.Tool.cyclonedx.mode.bom.BomMetaData.tools is of type cyclonedx.model.tool.ToolRepository now, was SortedSet[cyclonedx.model.Tool].cyclonedx.mode.vulnerability.Vulnerability.tools is of type cyclonedx.model.tool.ToolRepository now, was SortedSet[cyclonedx.model.Tool].cyclonedx.model.license.LicenseExpression() accepts optional argument acknowledgement only as key-word argument, no longer as positional argument.cyclonedx.model.bom.BomMetaData also accepts an instance of cyclonedx.model.tool.ToolRepositorycyclonedx.model.bom.BomMetaData no longer adds this very library as a tool. Downstream users may do so by utilizing cyclonedx.builder.this.this_tool().Enabled Metadata Tools representation and serialization in accordance with CycloneDX 1.5
cyclonedx.model.tool.ToolRepository.cyclonedx.builder.this.this_component() -- representation of this very python library as a Component.cyclonedx.builder.this.this_tool() -- representation of this very python library as a Tool.cyclonedx.model.tool.Tool.from_component().py-serializable>=1.1.1,<2, was >=1.1.0,<2.rendered docs preview: https://cyclonedx-python-library.readthedocs.io/en/8.0.0-dev/
Property cyclonedx.mode.vulnerability.Vulnerability.tools is of type cyclonedx.model.tool.ToolsRepository now, was SortedSet[cyclonedx.model.Tool]. Th…
cyclonedx.mode.ThisTool, utilize cyclonedx.builder.this.this_tool() instead.cyclonedx.model.Tool to cyclonedx.model.tool.Tool.cyclonedx.mode.bom.BomMetaData.tools is of type cyclonedx.model.tool.ToolsRepository now, was SortedSet[cyclonedx.model.Tool].cyclonedx.mode.vulnerability.Vulnerability.tools is of type cyclonedx.model.tool.ToolsRepository now, was SortedSet[cyclonedx.model.Tool].cyclonedx.model.license.LicenseExpression() accepts optional argument acknowledgement only as key-word argument, no longer as positional argument.cyclonedx.model.bom.BomMetaData also accepts an instance of cyclonedx.model.tool.ToolsRepositorycyclonedx.model.bom.BomMetaData no longer adds this very library as a tool. Downstream users may do so by utilizing cyclonedx.builder.this.this_tool().Enabled Metadata Tools representation and serialization in accordance with CycloneDX 1.5
cyclonedx.model.tool.ToolsRepository.cyclonedx.builder.this.this_component() -- representation of this very python library as a Component.cyclonedx.builder.this.this_tool() -- representation of this very python library as a Tool.cyclonedx.model.tool.Tool.from_component().py-serializable>=1.1.1,<2, was >=1.1.0,<2.rendered docs preview: https://cyclonedx-python-library.readthedocs.io/en/8.0.0-dev/
metafata.tools by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/674LicenseExpression() optional args are named args by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/595tomli by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/685Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.6.1...v8.0.0-rc.1
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`ce23b0f`)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (ce23b0f)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (bef268b)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (39514b3)
c123aff)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`cc09c42`)
fixes #681
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (cc09c42)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (4fa8fc1)
fixes #690
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (d8b20bd)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.6.1...v7.6.2
utilizes flake8 plugin <https://pypi.org/project/flake8-copyright-validator/> to assert the correct headers
utilizes flake8 plugin <https://pypi.org/project/flake8-copyright-validator/> to assert the correct headers
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (35e00b4)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.6.0...v7.6.1
feat: HashType.from_composite_str for Blake2b, SHA3, Blake3
HashType.from_composite_str for Blake2b, SHA3, Blake3 (#663)The code mistreated hashes for Blake2b and SHA3. Code for explicitly handling SHA1 & BLAKE3 was added, as those have no variants defined in the CycloneDX specification.
fixes #652
Signed-off-by: Michael Schlenker <michael.schlenker@contact-software.com>
Co-authored-by: Michael Schlenker <michael.schlenker@contact-software.com>
Co-authored-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c59036e)
HashType.from_composite_str for Blake2b, SHA3, Blake3 by @schlenk in https://github.com/CycloneDX/cyclonedx-python-lib/pull/663Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.5.1...v7.6.0
fix: XML serialize normalizedString and token properly
normalizedString and token properly (#646)fixes #638
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (b40f739)
normalizedString and token properly by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/646Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.5.0...v7.5.1
Property workaround was missing from the vulnerability model. It was added in spec v1.5 and was marked as TODO before.
Property workaround was missing from the vulnerability model. It was
added in spec v1.5 and was marked as TODO before.
This is my first contribution on this project so if I done something wrong, just say me :smiley:
Signed-off-by: Louis Maillard <louis.maillard@savoirfairelinux.com>
Signed-off-by: Louis Maillard <louis.maillard@protonmail.com>
Co-authored-by: Louis Maillard <louis.maillard@savoirfairelinux.com> (b5ebcf8)
this should make future PR reviews easier, since adding new args in the middle will not cause complete code blocks to change, but is just a new line ...
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (5b74b0f)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.4.1...v7.5.0
chore: rollback py sem release matcher
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c33a130)
fixes #616
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (60361f7)
cyclonedx.model.Property.value value is optional (#631)cyclonedx.model.Property.value value is optional, in accordance with
the spec.
fixes #630
Signed-off-by: Michael Schlenker <michael.schlenker@contact-software.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Co-authored-by: Michael Schlenker <michael.schlenker@contact-software.com>
Co-authored-by: Jan Kowalleck <jan.kowalleck@gmail.com> (ad0f98b)
docs: OSSP best practice percentage
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (75f58dc)
v3.24.0 (#622)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (3f9770a)
v3.24.0 by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/622Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.3.4...v7.4.0
fix: allow suppliers with empty-string names
fixes #600
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (b331aeb)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.3.3...v7.3.4
chore: shield_ossf-best-practices subbary
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (0d00496)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (6d1bc5b)
$schema value (#613)fixes https://github.com/CycloneDX/cyclonedx-python-lib/issues/612
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (08b7c60)
$schema value by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/613Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.3.2...v7.3.3
Your coding agent can read these notes before it upgrades. Set up the MCP server →