The CycloneDX module for Rust (Cargo) creates a valid CycloneDX Software Bill of Materials (SBOM) containing an aggregate of all project dependencies. OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard providing advanced supply chain capabilities for cyber risk reduction.
This repository contains two separate projects:
cyclonedx-bom
is a Rust library to read and write CycloneDX SBOMs to and from Rust structs.cargo-cyclonedx
is a Rust application, which generates CycloneDX SBOMs for Cargo based Rust projects (it usescyclonedx-bom
for that purpose).
Execute cargo-cyclonedx
from within a Rust project directory containing Cargo.toml.
cargo install cargo-cyclonedx
~/.cargo/bin/cargo-cyclonedx cyclonedx
cargo cyclonedx
Contributions are welcome.
See our CONTRIBUTING.md
for details.
We are running a Bug Bounty program financed by the Bug Resilience Program of the Sovereign Tech Fund. Thank you very much!
CycloneDX Rust Cargo is Copyright (c) OWASP Foundation. All Rights Reserved.
Permission to modify and redistribute is granted under the terms of the Apache 2.0 license. See the LICENSE file for the full license.