CycloneDX / CycloneDX/cyclonedx-python

Feature request: Add native uv project support (pyproject.toml + uv.lock) via cyclonedx-py uv subcommand

已关闭
#1,029 6 条评论 1 个 reaction 已指派 0 人 已被 @m7mdhka 认领 在 GitHub 查看
enhancement source: uv
主要语言
Python
星标
390
派生
98
平均合并
2 天 23 小时
30 天内合并 PR
2

描述

## Is your feature request related to a problem? Please describe.

Yes. `cyclonedx-py` currently supports generating SBOMs from environments, requirements, Pipenv, and Poetry projects, but there is no first-class `uv` project workflow in released versions.
This makes it harder for teams using `uv` to generate lockfile-based SBOMs directly from `pyproject.toml` + `uv.lock`, and can block adoption in projects where `uv` is the package manager of record.

## Describe the solution you'd like

Add native `uv` project support as a dedicated CLI subcommand (for example, `cyclonedx-py uv`) that:

- accepts a project directory (or `uv.lock` path),
- reads `pyproject.toml` and `uv.lock`,
- resolves dependency groups/extras in a way consistent with `uv`,
- generates CycloneDX JSON/XML output with the same quality and validation behavior as existing subcommands,
- is documented in `README` and `docs/usage.rst`,
- includes integration/unit tests and snapshot coverage.

## Describe alternatives you've considered

- **Environment scan (`cyclonedx-py environment`)**: works for installed packages, but is less lockfile-centric and can differ from the exact declared lock resolution.
- **Converting/exporting through external tools first**: adds extra steps and potential drift between source lock data and generated SBOM.
- **Maintaining custom scripts**: increases maintenance burden and reduces consistency with official tool behavior.

## Additional context

`uv` adoption is growing quickly, and users expect parity with other mainstream Python dependency workflows.
A dedicated `uv` subcommand would improve reproducibility, reduce friction in CI pipelines, and align with lockfile-driven supply chain practices.

## Contribution

- [x] I am willing to provide an implementation
- [ ] I will wait until somebody else implements it

贡献指南

打开贡献指南

调研方向

首先查看现有的 cyclonedx-py 子命令和链接的 pull request #1028,然后阅读 README 和 docs/usage.rst,了解文档中记录的 CLI 模式。完成的标准是:专用的 uv 工作流接受 pyproject.toml 和 uv.lock,生成所请求的 CycloneDX 输出,并具备所要求的 unit、integration 和 snapshot 覆盖率。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
cli, documentation, tooling
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
基本清楚
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。