CycloneDX / CycloneDX/cyclonedx-python

Feature request: Add native uv project support (pyproject.toml + uv.lock) via cyclonedx-py uv subcommand

Cerrado
#1,029 6 comentarios 1 reacción 0 asignados Reclamado por @m7mdhka Ver en GitHub
enhancement source: uv
Lenguaje dominante
Python
Estrellas
390
Forks
98
Merge medio
2 d 23 h
PR fusionados (30 d)
2

Descripción

## Is your feature request related to a problem? Please describe.

Yes. `cyclonedx-py` currently supports generating SBOMs from environments, requirements, Pipenv, and Poetry projects, but there is no first-class `uv` project workflow in released versions.
This makes it harder for teams using `uv` to generate lockfile-based SBOMs directly from `pyproject.toml` + `uv.lock`, and can block adoption in projects where `uv` is the package manager of record.

## Describe the solution you'd like

Add native `uv` project support as a dedicated CLI subcommand (for example, `cyclonedx-py uv`) that:

- accepts a project directory (or `uv.lock` path),
- reads `pyproject.toml` and `uv.lock`,
- resolves dependency groups/extras in a way consistent with `uv`,
- generates CycloneDX JSON/XML output with the same quality and validation behavior as existing subcommands,
- is documented in `README` and `docs/usage.rst`,
- includes integration/unit tests and snapshot coverage.

## Describe alternatives you've considered

- **Environment scan (`cyclonedx-py environment`)**: works for installed packages, but is less lockfile-centric and can differ from the exact declared lock resolution.
- **Converting/exporting through external tools first**: adds extra steps and potential drift between source lock data and generated SBOM.
- **Maintaining custom scripts**: increases maintenance burden and reduces consistency with official tool behavior.

## Additional context

`uv` adoption is growing quickly, and users expect parity with other mainstream Python dependency workflows.
A dedicated `uv` subcommand would improve reproducibility, reduce friction in CI pipelines, and align with lockfile-driven supply chain practices.

## Contribution

- [x] I am willing to provide an implementation
- [ ] I will wait until somebody else implements it

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.