NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #659 most downloaded on PyPI
Python library for CycloneDX
Last release 1 months ago
13 Aug 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
5 years old
160 releases · first in 2021
One column per quarter.
fix: properly sort components based on all properties
reverts #587 - as this one introduced errors fixes #598 fixes #586
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Paul Horton <paul.horton@owasp.org>
Co-authored-by: Paul Horton <paul.horton@owasp.org> (8df488c)
chore: semantic-release git commit/sign valid email address
feat: license factory set acknowledgement
acknowledgement (#593)add a parameter to LicenseFactory.make_*() methods, to set the LicenseAcknowledgement.
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (7ca2455)
feat: disjunctive license acknowledgement
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (9bf1839)
When packaging cyclonedx-python-lib for a Linux distribution, it’s pretty common that some JSON validation tests fail. 1
Due to the large number of combinations and the fact that these tests are consecutively numbered, it has been tedious to figure out which tests are exactly failing and why. This in turn makes it difficult to decide which tests to disable or report upstream.
Append meaningful names to validation tests so that instead of e.g.:
[…]::TestJsonValidator::test_validate_no_none_001
[…]::TestJsonValidator::test_validate_no_none_002
[…]::TestJsonValidator::test_validate_no_none_003
[…]::TestJsonValidator::test_validate_no_none_004
[…]::TestJsonValidator::test_validate_no_none_005
[…]::TestJsonValidator::test_validate_no_none_006
[…]::TestJsonValidator::test_validate_no_none_007
[…]::TestJsonValidator::test_validate_no_none_008
the tests are named:
[…]::TestJsonValidator::test_validate_no_none_001_valid_component_swid_1_6
[…]::TestJsonValidator::test_validate_no_none_002_valid_machine_learning_considerations_env_1_6
[…]::TestJsonValidator::test_validate_no_none_003_valid_metadata_tool_1_6
[…]::TestJsonValidator::test_validate_no_none_004_valid_patch_1_6
[…]::TestJsonValidator::test_validate_no_none_005_valid_empty_components_1_6
[…]::TestJsonValidator::test_validate_no_none_006_valid_properties_1_6
[…]::TestJsonValidator::test_validate_no_none_007_valid_service_1_6
[…]::TestJsonValidator::test_validate_no_none_008_valid_metadata_author_1_6
Signed-off-by: Claudia <claui@users.noreply.github.com> (ae3f79c)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (a498faa)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.1.0...v7.2.0
docs: missing schema support table & update schema support to reflect version 7.0.0
Signed-off-by: Paul Horton <paul.horton@owasp.org> (d230e67)
bom.properties for CycloneDX v1.5+ (#585)Signed-off-by: Paul Horton <paul.horton@owasp.org> (1d1c45a)
bom.properties for CycloneDX v1.5+ by @madpah in https://github.com/CycloneDX/cyclonedx-python-lib/pull/585Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v7.0.0...v7.1.0
note bom.metadata.manufacture as deprecated
bom.metadata.manufacture as deprecatedbom.metadata for v1.6.component.author. Added .component.authors and .component.manufacturer.component.omniborid - but tests deserialisation tests fail due to schema differences (.component.author not in 1.6)py-serializable to >=1.0.3 to resolve issues with deserialization to XML.component.swhid.component.cryptoProperties - with test failures for SchemaVersion < 1.6address to organizationalEntityaddress to organizationalEntityUserWarning in .component.version has length > 1024acknowledgement to LicenseExpression (#582)Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.4.4...v7.0.0
Deprecated .component.author. Added .component.authors and .component.manufacturer
py-serializable to >=1.0.3 to resolve issues with deserialization to XMLSigned-off-by: Paul Horton <paul.horton@owasp.org> (0398051)
Updates the requirements on autopep8 to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (35749c6)
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (d60f457)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (42c6f25)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (b4a133a)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (0843234)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (62c1d9a)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (e10ffee)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (e0184cc)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (618a292)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (289e81a)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (0449de2)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (0a2ca2c)
acknowledgement to LicenseExpression (#582)Signed-off-by: Paul Horton <paul.horton@owasp.org> (ddd7847)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (5c97c2d)
UserWarning in .component.version has length > 1024Signed-off-by: Paul Horton <paul.horton@owasp.org> (abebd4f)
address to organizationalEntitySigned-off-by: Paul Horton <paul.horton@owasp.org> (1327558)
address to organizationalEntitySigned-off-by: Paul Horton <paul.horton@owasp.org> (318d723)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (d294620)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (71e4bc6)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (f504daa)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (a3e09d1)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (14f699f)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (b23df1f)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (96a6dc9)
.component.cryptoProperties - with test failures for SchemaVersion < 1.6Signed-off-by: Paul Horton <paul.horton@owasp.org> (1e71dc3)
.component.swhidSigned-off-by: Paul Horton <paul.horton@owasp.org> (ee80ea3)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (875a338)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (fdece59)
.component.omniborid - but tests deserialisation tests fail due to schema differences (.component.author not in 1.6)Signed-off-by: Paul Horton <paul.horton@owasp.org> (af7b92b)
.component.author. Added .component.authors and .component.manufacturerSigned-off-by: Paul Horton <paul.horton@owasp.org> (6227c08)
bom.metadata for v1.6Signed-off-by: Paul Horton <paul.horton@owasp.org> (6192ed8)
bom.metadata.manufacture as deprecatedSigned-off-by: Paul Horton <paul.horton@owasp.org> (240dfaa)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (8132c3e)
Signed-off-by: Paul Horton <paul.horton@owasp.org> (41ca1e0)
chore(deps-dev): update coverage requirement from 7.4.3 to 7.4.4
Updates the requirements on coverage to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (3a2e427)
Bumps python-semantic-release/python-semantic-release from 8.5.1 to 9.1.1.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (d20a590)
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (2dcc60e)
Updates the requirements on bandit to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (eb1a252)
Updates the requirements on mypy to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (3ce0f3a)
Signed-off-by: Christoph Reiter <reiter.christoph@gmail.com> (10e38e2)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.4.3...v6.4.4
chore(deps-dev): update ddt requirement from 1.7.1 to 1.7.2
Updates the requirements on ddt to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (53cb8a9)
model.component.Diff (#557)Fixes #556
Signed-off-by: rcross-lc <151086351+rcross-lc@users.noreply.github.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Co-authored-by: Jan Kowalleck <jan.kowalleck@gmail.com> (22fa873)
model.component.Diff by @rcross-lc in https://github.com/CycloneDX/cyclonedx-python-lib/pull/557Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.4.2...v6.4.3
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`6f81dfa`)
Maintenance release.
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (6f81dfa)
Updates the requirements on coverage to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (2b7f261)
Bumps Gr1N/setup-poetry from 8 to 9.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (178ce32)
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (77fb2ec)
Updates the requirements on flake8-quotes to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (cd8e67c)
Updates the requirements on flake8-bugbear to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (153d83e)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (a19fd28)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (7e55dfe)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (63cff7e)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (b0e5b43)
chore(deps-dev): update bandit requirement from 1.7.6 to 1.7.7
Updates the requirements on bandit to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (0d159c2)
Updates the requirements on coverage to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (fa82a24)
sdist build (#544)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (52ef01c)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c1776b7)
fix: model.BomRef no longer equal to unset peers (#543)
fixes #539
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (1fd7fee)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (394cc87)
sdist build by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/544model.BomRef no longer equal to unset peers by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/543Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.4.0...v6.4.1
chore(deps-dev): update tox requirement from 4.12.0 to 4.12.1
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (74094d7)
Updates the requirements on flake8-bugbear to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (6e6f374)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (bd4c078)
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (130918a)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (59c4381)
py-serializable v1.0 (#531)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (e1e7277)
chore(deps-dev): update flake8 requirement from 6.1.0 to 7.0.0
Updates the requirements on flake8 to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (6b7ed78)
Updates the requirements on ddt to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (9a58e7e)
Documentation url to project metaSigned-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (1080b73)
Documentation url to project metaSigned-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c4288b3)
py-serializable 0.17 (#529)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (9f24220)
py-serializable 0.17 by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/529Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.2.0...v6.3.0
build: allow additional major-version RC branch patterns
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (f8af156)
Updates the requirements on coverage to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (9bcc223)
Updates the requirements on mypy to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (720046e)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (2563996)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (f0bd05d)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (b3e9ab7)
lxml requirement in range of >=4,<6 (#523)Updates the requirements on lxml to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (7d12b9a)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (7dcd166)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.1.0...v6.2.0
f8af156)Buld docs on ubuntu22.04 python311
(b3e9ab7)
Fix typo
(2563996)
Update intro and description
(f0bd05d)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`87c72d7`)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (87c72d7)
Bumps python-semantic-release/python-semantic-release from 8.5.0 to 8.5.1.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (0f56ec4)
Updates the requirements on coverage to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (a57e2f6)
Updates the requirements on isort to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (84874a3)
hashlib algorithms to CycloneDX (#519)new API: model.HashType.from_hashlib_alg()
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (81f8cf5)
hashlib algorithms to CycloneDX by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/519Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.0.0...v6.1.0
Removed model.vulnerability.Vulnerability.__init__()'s deprecated optional kwarg source_name (via [#493]) Use kwarg source instead.
parser.* (#489 via #495)output.LATEST_SUPPORTED_SCHEMA_VERSION (#491 via #494)model.component.Component with unsupported type raises exception.serialization.SerializationOfUnsupportedComponentTypeException (#490 via #496)model.bom_ref.BomRef's property value defaults to Null, was arbitrary UUID (#504 via #505)bom-refs are guaranteed to have unique values on rendering.py-serializable@^0.16, was @^0.15 (via #496)exception.serialization (via #496)models.ComparableTuple (#503 via #506)model.ExternalReferenceType got new cases, to reflect features for CycloneDX 1.5 (#404 via #488)models.get_now_utc (#503 via #506)models.sha1sum (#503 via #506)model.component.ComponentType got new cases, to reflect features for CycloneDX 1.5 (#404 via #488)model.component.Component.__init__()'s deprecated optional kwarg namespace (via #493)group instead.model.component.Component.__init__()'s deprecated optional kwarg license_str (via #493)licenses instead.model.component.Component.get_namespace() (via #493)models.dependency.DependencyDependencies (#503 via #506)model.vulnerability.Vulnerability.__init__()'s deprecated optional kwarg source_name (via #493)source instead.model.vulnerability.Vulnerability.__init__()'s deprecated optional kwarg source_url (via #493)source instead.model.vulnerability.Vulnerability.__init__()'s deprecated optional kwarg recommendations (via #493)recommendation instead.model.vulnerability.VulnerabilityRating.__init__()'s deprecated optional kwarg score_base (via #493)score instead.model.vulnerability.VulnerabilityScoreSource got new cases, to reflect features for CycloneDX 1.5 (#404 via #488)output.LATEST_SUPPORTED_SCHEMA_VERSION (#491 via #494)output.get_instance() (via #493)output.make_outputter() instead.output.json.JsonV1Dot5, to reflect CycloneDX 1.5 (#404 via #488)output.json.BY_SCHEMA_VERSION, to reflect CycloneDX 1.5 (#404 via #488)output.xml.XmlV1Dot5, to reflect CycloneDX 1.5 (#404 via #488)output.xml.BY_SCHEMA_VERSION, to reflect CycloneDX 1.5 (#404 via #488)parser.ParserWarning (#489 via #495)parser.BaseParser (#489 via #495)schema.SchemaVersion got new case V1_5, to reflect CycloneDX 1.5 (#404 via #488)Signed-off-by: Johannes Feichtner <johannes@web-wack.at>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: semantic-release <semantic-release>
Co-authored-by: Johannes Feichtner <343448+Churro@users.noreply.github.com>
Co-authored-by: semantic-release <semantic-release> (74865f8)
Bumps python-semantic-release/python-semantic-release from 8.0.8 to 8.5.0.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (9ed9ab1)
Updates the requirements on isort to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (0eba631)
Updates the requirements on bandit to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (153b07a)
Bumps actions/setup-python from 4 to 5.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (4e3e0e0)
Updates the requirements on sphinx-rtd-theme to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (5d6dd41)
Updates the requirements on flake8-bugbear to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (e9a12b9)
Updates the requirements on py-serializable to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (04435ab)
Updates the requirements on tox to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (8bf0e39)
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v5.2.0...v6.0.0
v6.0.0-rc.3 Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.0.0-rc.2...v6.0.0-rc.3
Build process was modernized
see the details here: https://github.com/CycloneDX/cyclonedx-python-lib/pull/492
v6.0.0-rc.3 Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.0.0-rc.2...v6.0.0-rc.3
see https://github.com/CycloneDX/cyclonedx-python-lib/pull/492
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v5.2.0...v6.0.0-rc.3
Object model.bom_ref.BomRef's property value defaults to Null, was arbitrary UUID ([#504] via [#505]) This change does not affect serialization. All b
model.bom_ref.BomRef's property value defaults to Null, was arbitrary UUID (#504 via #505)bom-refs are guaranteed to have unique values on rendering.see the details here: https://github.com/CycloneDX/cyclonedx-python-lib/pull/492
v6.0.0-rc.2 Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v6.0.0-rc.1...v6.0.0-rc.2
see https://github.com/CycloneDX/cyclonedx-python-lib/pull/492
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v5.2.0...v6.0.0-rc.2
Removed model.vulnerability.Vulnerability.__init__()'s optional kwarg source_name (via [#493]) Use kwarg source instead.
parser.* (#489 via #495)output.LATEST_SUPPORTED_SCHEMA_VERSION (#491 via #494)model.component.Component with unsupported type raises exception.serialization.SerializationOfUnsupportedComponentTypeException (#490 via #496)py-serializable@^0.16, was @^0.15 (via #496)exception.serialization (via #496)model.ExternalReferenceType got new cases, to reflect features for CycloneDX 1.5 (#404 via #488)model.component.ComponentType got new cases, to reflect features for CycloneDX 1.5 (#404 via #488)model.component.Component.__init__()'s optional kwarg namespace (via #493)group instead.model.component.Component.__init__()'s optional kwarg license_str (via #493)licenses instead.model.component.Component.get_namespace() (via #493)model.vulnerability.Vulnerability.__init__()'s optional kwarg source_name (via #493)source instead.model.vulnerability.Vulnerability.__init__()'s optional kwarg source_url (via #493)source instead.model.vulnerability.Vulnerability.__init__()'s optional kwarg recommendations (via #493)recommendation instead.model.vulnerability.VulnerabilityRating.__init__()'s optional kwarg score_base (via #493)score instead.model.vulnerability.VulnerabilityScoreSource got new cases, to reflect features for CycloneDX 1.5 (#404 via #488)output.LATEST_SUPPORTED_SCHEMA_VERSION (#491 via #494)output.get_instance() (via #493)output.make_outputter() instead.output.json.JsonV1Dot5, to reflect CycloneDX 1.5 (#404 via #488)output.json.BY_SCHEMA_VERSION, to reflect CycloneDX 1.5 (#404 via #488)output.xml.XmlV1Dot5, to reflect CycloneDX 1.5 (#404 via #488)output.xml.BY_SCHEMA_VERSION, to reflect CycloneDX 1.5 (#404 via #488)parser.ParserWarning (#489 via #495)parser.BaseParser (#489 via #495)schema.SchemaVersion got new case V1_5, to reflect CycloneDX 1.5 (#404 via #488)output.LATEST_SUPPORTED_SCHEMA_VERSION by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/494Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v5.1.1...v6.0.0-rc.1
chore(deps-dev): update mypy requirement from 1.7.0 to 1.7.1
Updates the requirements on mypy to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (78957e6)
Updates the requirements on mypy to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (c716ba3)
Updates the requirements on ddt to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (8a1f7b9)
see https://python-poetry.org/docs/managing-dependencies/#dependency-groups
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (a85585c)
Updates the requirements on flake8-isort to permit the latest version.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (fc74ddd)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (3189e59)
model.XsUri migrate control characters according to spec (#498)fixes https://github.com/CycloneDX/cyclonedx-python-lib/issues/497
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (e490429)
fix: update own externalReferences
externalReferences (#480)externalReferences by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/480Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v5.1.0...v5.1.1
docs: advance license docs (`f61a730`)
f61a730)BomRefs in serialization result (#479) (a648775)
Incorporate output.BomRefDiscriminator on serializationBomRefs in serialization result by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/479Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v5.0.1...v5.1.0
chore(deps): bump python-semantic-release/python-semantic-release
Bumps python-semantic-release/python-semantic-release from 8.0.8 to 8.3.0.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (9c3ffac)
pyproject parsable by dependabot (#477)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c4eaaa5)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c3254d0)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (b9fcfb4)
This reverts commit 9c3ffac34e89610ccc4f9701444127e1e6f5ee07.
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (aae7304)
pyproject parsable by dependabot by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/477Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v5.0.0...v5.0.1
New function output.make_outputter() (via [#469]) This replaces the deprecated function output.get_instance().
schema.SchemaVersion is no longer string-like (#442 via #447)schema.OutputVersion is no longer string-like (#442 via #447)output.BaseOutput requires implementation of new method output_format (#446 via #447)output.BaseOutput.output_as_string() got new optional parameter indent (#437 via #458)output.BaseOutput.output_as_string() accepts arbitrary kwargs (via #458, #462)factory.license.LicenseChoiceFactory (via #466)factory.license.LicenseFactory.factory.license.LicenseFactory.make_from_string()'s parameter name_or_spdx was renamed to value (via #466)factory.license.LicenseFactory.make_from_string()'s return value can also be a LicenseExpression (#365 via #466)factory.license.LicenseChoiceFactory.make_from_string()module.License to module.license.DisjunctliveLicense (#365 via #466)module.LicenseChoice (#365 via #466)module.license.DisjunctliveLicense and module.license.LicenseExpression insteadmodels.LicenseChoice were replaced by models.licenses.License (#365 via #466)SortedSet[LicenseChoice] were specialized to models.license.LicenseRepository (#365 via #466)model.bom.validate() (via #464)output.make_outputter() (via #469)output.get_instance().validation (#432, #446 via #433, #448, #469, #468, #469)exception.MissingOptionalDependencyException (#432 via #433)exception.LicenseExpressionAlongWithOthersException (#453 via #452)output.{json,xml}.BY_SCHEMA_VERSION (#446 via #447)output.BaseOutput now have a new method output_format (#446 via #447)output.BaseOutput.output_as_string() got new optional parameter indent (#437 via #458)output.BaseOutput.output_to_file() got new optional parameter indent (#437 via #458)factory.license.LicenseFactory.make_with_expression() (via #466)model.license.DisjunctiveLicense (#365 via #466)model.license.LicenseExpression (#365 via #466)model.license.LicenseRepository (#365 via #466)serialization.LicenseRepositoryHelper (#365 via #466)output.get_instance() might be removed, use output.make_outputter() instead (via #469)py-serializable@^0.15.0, was @^0.11.1 (via #458, #463, #464, #466)Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v4.2.3...v5.0.0
read the [full change log](https://github.com/CycloneDX/cyclonedx-python-lib/pull/440).
read the full change log.
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (bc8e30b)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (2967f28)
Signed-off-by: Jan Kowalleck <jan.kowalleck@owasp.org> (9373afc)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (e298726)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (a2af2ed)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (bb0f7a5)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (d09ac36)
c4f7281)get_instance() by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/469Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v5.0.0-rc.1...v5.0.0-rc.2
Dropped support for python<3.8 ([#436] via [#441]; enable [#433])
schema.SchemaVersion is no longer string-like (#442 via #447)schema.OutputVersion is no longer string-like (#442 via #447)output.BaseOutput requires implementation of new method output_format (#446 via #447)output.BaseOutput.output_as_string() got new optional parameter indent (#437 via #458)output.BaseOutput.output_as_string() accepts arbitrary kwargs (via #458, #462)factory.license.LicenseChoiceFactory (via #466)factory.license.LicenseFactory.factory.license.LicenseFactory.make_from_string()'s parameter name_or_spdx was renamed to value (via #466)factory.license.LicenseFactory.make_from_string()'s return value can also be a LicenseExpression (#365 via #466)factory.license.LicenseChoiceFactory.make_from_string()module.License to module.license.DisjunctliveLicense (#365 via #466)module.LicenseChoice (#365 via #466)module.license.DisjunctliveLicense and module.license.LicenseExpression insteadmodels.LicenseChoice were replaced by models.licenses.License (#365 via #466)SortedSet[LicenseChoice] were specialized to models.license.LicenseRepository (#365 via #466)model.bom.validate() (via #464)validation (#432, #446 via #433, #448)exception.MissingOptionalDependencyException (#432 via #433)exception.LicenseExpressionAlongWithOthersException (#453 via #452)output.{json,xml}.BY_SCHEMA_VERSION (#446 via #447)output.BaseOutput now have a new method output_format (#446 via #447)output.BaseOutput.output_as_string() got new optional parameter indent (#437 via #458)output.BaseOutput.output_to_file() got new optional parameter indent (#437 via #458)factory.license.LicenseFactory.make_with_expression() (via #466)model.license.DisjunctiveLicense (#365 via #466)model.license.LicenseExpression (#365 via #466)model.license.LicenseRepository (#365 via #466)serialization.LicenseRepositoryHelper (#365 via #466)py-serializable@^0.15.0, was @^0.11.1 (via #458, #463, #464, #466)bom.validate() detects invalid license constellations by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/452kwargs by @jkowalleck in https://github.com/CycloneDX/cyclonedx-python-lib/pull/462Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v4.2.2...v5.0.0-rc.1
Signed-off-by: Jan Kowalleck <jan.kowalleck@owasp.org> (`0ebaa21`)
Signed-off-by: Jan Kowalleck <jan.kowalleck@owasp.org> (0ebaa21)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (0012a82)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (5fa66a0)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (`49b144b`)
fixes #430
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (49b144b)
Bumps actions/checkout from 3 to 4.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (a70754d)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (6a941b1)
LicenseChoiceFactory (#428)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (c56ec83)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (3a1a8a5)
fix: LicenseChoiceFactory.make_from_string() prioritize SPDX id over expression
LicenseChoiceFactory.make_from_string() prioritize SPDX id over expression (#427)Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (e1bdfdd)
chore(deps): bump python-semantic-release/python-semantic-release
Bumps python-semantic-release/python-semantic-release from 8.0.7 to 8.0.8.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (13e441d)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (e06f9fd)
chore: migrate to python-semantic-release8
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (14c501c)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (0e35d88)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (adf5a36)
Bumps distlib from 0.3.6 to 0.3.7.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (bc9f01d)
Bumps pluggy from 1.0.0 to 1.2.0.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (be8af3e)
Bumps typed-ast from 1.5.4 to 1.5.5.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (75302b1)
Bumps lxml from 4.9.2 to 4.9.3.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (6aa057b)
Bumps mypy from 1.4.0 to 1.4.1.
updated-dependencies:
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (54d6a1a)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (6a7ddfa)
ci: run examples on prod-deps only (#402)
ci: run examples on prod-deps only
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (cf40048)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (058f386)
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (8b32efb)
adds cyclonedx.__version__
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com> (3585ea9)
Conditional warning if no root dependencies were found (#398) (`c8175bb`)
Model classes changed to relocated Vulnerability at Bom, not at Component (`8fb1b14`)
8fb1b14)8fb1b14)8fb1b14)8fb1b14)8fb1b14)Remove toml as dependency as not used and seems to be breaking Python 3.11 CI
(8fb1b14)
Removed autopep8 in favour of flake8 as both have conflicting dependencies now
(8fb1b14)
Removed setuptools as dependency
(8fb1b14)
Removed types-toml from dependencies - not used
(8fb1b14)
Update serializable to include XML safety changes
(8fb1b14)
Add helper method to get URN for a BOM according to
https://www.iana.org/assignments/urn-formal/cdx
(8fb1b14)
Allow serial_number of BOM to be prescribed
(8fb1b14)
Allow version of BOM to be defined
(8fb1b14)
Drop Python 3.6 support
(8fb1b14)
Officially test and support Python 3.11
(8fb1b14)
Release 4.0.0 #341)
(8fb1b14)
Support for deserialization from JSON and XML
(#290,
8fb1b14)
Support VEX without Components in the same BOM
(8fb1b14)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Mak test's schema paths relative to cyclonedx package (#338) (`1f0c05f`)
tests: Include tests in sdist builds (#337) (`936ad7d`)
Serialize dependency graph for nested components (#329) (`fb3f835`)
Prevent errors on metadata handling for some specification versions (#330) (`f08a656`)
Type hint for get_component_by_purl is incorrect (`3f20bf0`)
get_component_by_purl is incorrect (3f20bf0)get_component_by_purl is incorrect
(3f20bf0)…and subsequently yanked from PyPi. There are NO breaking changes between 2.7.1 and 3.1.0.
Note: There was no 3.0.0 release officially, but due to CI publishing issues, an unexpected 3.0.0 release was publiched to PyPi and subsequently yanked from PyPi. There are NO breaking changes between 2.7.1 and 3.1.0.
Nothing published for this version
Nothing published for this version
chore(deps-dev): bump flake8-isort from 4.1.1 to 4.1.2.post0 by @dependabot in https://github.com/CycloneDX/cyclonedx-python-lib/pull/280
Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v2.7.0...v2.7.1
feature: support for CycloneDX schema 1.4.2 - adds vulnerability.properties to the schema by @madpah in https://github.com/CycloneDX/cyclonedx-python-…
1.4.2 - adds vulnerability.properties to the schema by @madpah in https://github.com/CycloneDX/cyclonedx-python-lib/pull/273Full Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v2.6.0...v2.7.0
Reduce unnessessarry type casting of set/SortedSet (#203) (`089d971`)
Add expected lower-than comparators for OrganizationalEntity and VulnerabilityCredits (#248) (`0046ee1`)
Add missing Vulnerability comparator for sorting (#246) (`c3f3d0d`)
Use SortedSet in model to improve reproducibility - this will provide predictable ordering of various items in generated CycloneDX documents - thanks
0e2376b)ef0278a)SortedSet in model to improve reproducibility - this will provide predictable ordering of
various items in generated CycloneDX documents - thanks to @RodneyRichardson
(8a1c404)deps: Remove unused typing-extensions constraints (`2ce358a`)
typing-extensions constraints (2ce358a)typing-extensions constraints
(2ce358a)Add support for Dependency Graph in Model and output serialisation (`ea34513`)
ea34513)Bump XML schemas to latest fix version for 1.2-1.4 - see: (`bd2e756`)
Prevent error if version not set (`b9a84b5`)
Output errors are verbose (`bfe8fb1`)
bfe8fb1)Completed work on #155 (#172) (`a926b34`)
da3f0ca)a926b34)bom.metadata (#162) (2938a6c)bom.externalReferences in JSON and XML #124 (1b733d7)bom.components (#155) (32c0139)9edf6c9)license_url not serialised in XML output #179 (#180) (f014d7c)Component.bom_ref is not Optional in our model implementation (in the schema it is) - we generate a UUID if bom_ref is not supplied explicitly (5c954d1)__hash__ of Component with properties #153 (a51766d)1f55f3e)c09e396)70d25c8)expression not supported in Component Licsnes for version 1.0 (15b081b)BomRef data typecomponent.bom_ref is not Optional in our model implementation (in the schema it is) - we
generate a UUID if bom_ref is not supplied explicitly
(5c954d1)
expression not supported in Component Licsnes for version 1.0
(15b081b)
license_url not serialised in XML output #179
(#180,
f014d7c)
Components with no version (optional since 1.4) produce invalid BOM output in XML #150
(70d25c8)
Further fix for #150
(1f55f3e)
Implemented correct __hash__ methods in models
(#155,
32c0139)
Regression introduced by first fix for #150
(c09e396)
Temporary fix for __hash__ of Component with properties #153
(a51766d)
bom-ref for Component and Vulnerability default to a UUID
(#142,
b45ff18)
bom-ref for Component and Vulnerability default to a UUID if not supplied ensuring they have a
unique value #141
(b45ff18)
Bump dependencies
(da3f0ca)
Support for bom.externalReferences in JSON and XML #124
(1b733d7)
Support services in XML BOMs
(9edf6c9)
Adopt PEP-3102
Optional Lists are now non-optional Sets
Remove concept of DEFAULT schema version - replaced with LATEST schema version
Added BomRef data type
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →