NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #659 most downloaded on PyPI
Python library for CycloneDX
Last release 1 months ago
13 Aug 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
5 years old
160 releases · first in 2021
One column per quarter.
Nothing published for this version
Nothing published for this version
bom-ref for Component and Vulnerability default to a UUID (#142) (`3953bb6`)
Add CPE to component (#138) (`269ee15`)
Bump dependencies (#136) (`18ec498`)
Add support for bom.metadata.component (#118) (`1ac31f4`)
Support for the core schema implementation of Vulnerabilities (VEX)
Support for CycloneDX schema version 1.4 (#108)
Support for CycloneDX 1.4. This includes:
tools having externalReferencesversion for a Component to be optional in 1.4releaseNotes per Component$schema is now included in JSON BOMsXsUri class to provide URI validationFull Changelog: https://github.com/CycloneDX/cyclonedx-python-lib/compare/v0.12.3...v1.0.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Removed requirements-parser as dependency (temp) as not available for Python 3 as Wheel (#98) (`3677d9f`)
Tightened dependency packageurl-python (#95) (`eb4ae5c`)
Further loosened dependency definitions (`8bef6ec`)
8bef6ec)8bef6ec)Loosed dependency versions to make this library more consumable (`55f10fb`)
55f10fb)Typing definitions to be PY 3.6 compatible
(07ebedc)
Update conda package parsing to handle build containing underscore
(#66,
2c6020a)
Loosed dependency versions to make this library more consumable
(55f10fb)
Lowering minimum dependency versions
(55f10fb)
Lowering minimum dependency versions - importlib-metadata raising minimum to ensure we get a typed
library
(55f10fb)
Lowering minimum version for importlib-metadata to 3.4.0 with modified import statement
(55f10fb)
Constructor for Vulnerability to correctly define ratings as optional (`395a0ec`)
Vulnerability to correctly define ratings as optional (395a0ec)### Feature * Typing & PEP 561 (`9144765`)
9144765)Correct way to write utf-8 encoded files (`49f9369`)
49f9369)49f9369)Ensure output to file is UTF-8 (`a10da20`)
Add support for Conda (`bd29c78`)
bd29c78)Missing check for Classifiers in Environment Parser (`b7fa38e`)
b7fa38e)Add support for parsing package licenses when using the Environment Parsers (`c414eaf`)
Environment Parsers (c414eaf)b7fa38e)Environment Parsers
(c414eaf)Coding standards violations (`00cd1ca`)
Add namespace and subpath support to Component to complete PackageURL Spec support (`780adeb`)
780adeb)780adeb)Multiple hashes being created for an externalRefernce which is not as required (`970d192`)
970d192)970d192)Add support for externalReferneces for Components and associated enhancements to parsers to obtain information where possible/known (`a152852`)
externalReferneces for Components and associated enhancements to parsers to obtain information where possible/known (a152852)Support for pipenv.lock file parsing (`68a2dff`)
68a2dff)68a2dff)Added ability to add tools in addition to this library when generating CycloneDX + plus fixes relating to multiple BOM instances (`e03a25c`)
e03a25c)Better methods for checking if a Component is already represented in the BOM, and the ability to get the existing instance (`5fee85f`)
5fee85f)Helper method for representing a File as a Component taking into account versioning for files as per https://github.com/CycloneDX/cyclonedx.org/issues
Add support for tool(s) that generated the SBOM (`7d1e6ef`)
efc1053)6a9947d)7d1e6ef)Improved handling for requirements.txt content without pinned or declared versions (`7f318cb`)
requirements.txt content without pinned or declared versions (7f318cb)requirements.txt content without pinned or declared versions
(7f318cb)0411826)Support for localising vectors (i.e. stripping out any scheme prefix) (`b9e9e17`)
Relaxed typing of parameter to be compatible with Python < 3.9
(f9c7990)
Remove unused commented out code
(ba4f285)
Removed print call
(8806553)
Removed print call
(d272d2e)
Adding support for extension schema that descriptions vulnerability disclosures (`d496695`)
d496695)d496695)Added helper method to return a PackageURL object representing a Component (`367bef1`)
### Feature * Add poetry support (`f3ac42f`)
f3ac42f)test: Test was not updated for revised author statement (`d1c9d37`)
### Fix * Add in pypi badge (`6098c36`)
6098c36)Additional info to poetry, remove circleci (`2fcfa5a`)
2fcfa5a)Initial release to pypi, tell poetry to include cyclonedx package (`a030177`)
a030177)2fcfa5a)Your coding agent can read these notes before it upgrades. Set up the MCP server →