CycloneDX / CycloneDX/cyclonedx-python
Feature request: Add native uv project support (pyproject.toml + uv.lock) via cyclonedx-py uv subcommand
- 主要语言
- Python
- 星标
- 390
- 派生
- 98
- 平均合并
- 2 天 23 小时
- 30 天内合并 PR
- 2
描述
## Is your feature request related to a problem? Please describe.
Yes. `cyclonedx-py` currently supports generating SBOMs from environments, requirements, Pipenv, and Poetry projects, but there is no first-class `uv` project workflow in released versions.
This makes it harder for teams using `uv` to generate lockfile-based SBOMs directly from `pyproject.toml` + `uv.lock`, and can block adoption in projects where `uv` is the package manager of record.
## Describe the solution you'd like
Add native `uv` project support as a dedicated CLI subcommand (for example, `cyclonedx-py uv`) that:
- accepts a project directory (or `uv.lock` path),
- reads `pyproject.toml` and `uv.lock`,
- resolves dependency groups/extras in a way consistent with `uv`,
- generates CycloneDX JSON/XML output with the same quality and validation behavior as existing subcommands,
- is documented in `README` and `docs/usage.rst`,
- includes integration/unit tests and snapshot coverage.
## Describe alternatives you've considered
- **Environment scan (`cyclonedx-py environment`)**: works for installed packages, but is less lockfile-centric and can differ from the exact declared lock resolution.
- **Converting/exporting through external tools first**: adds extra steps and potential drift between source lock data and generated SBOM.
- **Maintaining custom scripts**: increases maintenance burden and reduces consistency with official tool behavior.
## Additional context
`uv` adoption is growing quickly, and users expect parity with other mainstream Python dependency workflows.
A dedicated `uv` subcommand would improve reproducibility, reduce friction in CI pipelines, and align with lockfile-driven supply chain practices.
## Contribution
- [x] I am willing to provide an implementation
- [ ] I will wait until somebody else implements it
贡献指南
调研方向
首先查看现有的 cyclonedx-py 子命令和链接的 pull request #1028,然后阅读 README 和 docs/usage.rst,了解文档中记录的 CLI 模式。完成的标准是:专用的 uv 工作流接受 pyproject.toml 和 uv.lock,生成所请求的 CycloneDX 输出,并具备所要求的 unit、integration 和 snapshot 覆盖率。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- cli, documentation, tooling
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100