CycloneDX/specification
View on GitHubOWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and VEX
- Stars
- 547
- Forks
- 93
- Open beginner issues
- 0
- Indexed issues
- 179
- Avg merge
- 7h 11m
- Merged PRs (30d)
- 37
- Dominant language
- XSLT
- License
- Apache-2.0
- Last GitHub push
- Sep 2, 2026
- Latest indexed
- Sep 15, 2026
- Contributing guide
- Contributing guide
- Code of conduct
- Code of conduct
- Beginner labels
- help wanted
-
CycloneDX/specification#976 · 0 comments · 0 reactions · 0 assignees ·
-
CDX 2.0 chore defect
CycloneDX/specification#988 · 0 comments · 0 reactions · 1 assignee ·
-
CDX 2.0 chore defect
CycloneDX/specification#989 · 0 comments · 0 reactions · 1 assignee ·
-
defect
CycloneDX/specification#1008 · 0 comments · 0 reactions · 1 assignee ·
-
CycloneDX/specification#1014 · 0 comments · 0 reactions · 0 assignees ·
-
CycloneDX/specification#1015 · 0 comments · 0 reactions · 0 assignees ·
-
CDX 2.0
CycloneDX/specification#1016 · 9 comments · 0 reactions · 0 assignees ·
-
CDX 1.7 defect format: XML validated
CycloneDX/specification#1018 · 2 comments · 0 reactions · 0 assignees ·
-
CDX 2.0
CycloneDX/specification#1024 · 0 comments · 0 reactions · 0 assignees ·
-
cap: cryptography-registry defect
CycloneDX/specification#1025 · 0 comments · 0 reactions · 0 assignees ·
-
cap: cryptography-registry defect
CycloneDX/specification#1028 · 0 comments · 0 reactions · 0 assignees ·
-
CDX 1.7 defect format: JSON format: XML
CycloneDX/specification#1030 · 1 comment · 0 reactions · 0 assignees ·
-
breaking-changes CDX 1.7
CycloneDX/specification#1031 · 4 comments · 0 reactions · 0 assignees ·
-
CDX 2.0 defect documentation
CycloneDX/specification#1033 · 5 comments · 0 reactions · 1 assignee ·
-
CDX 2.0 documentation ready for review
CycloneDX/specification#1035 · 0 comments · 0 reactions · 0 assignees ·
-
CDX 2.0 proposed core enhancement
CycloneDX/specification#1037 · 2 comments · 1 reaction · 1 assignee ·
-
defect
CycloneDX/specification#1045 · 0 comments · 0 reactions · 0 assignees ·
-
CDX 1.7 defect
CycloneDX/specification#1049 · 0 comments · 0 reactions · 1 assignee ·
-
CDX 2.0 defect documentation
CycloneDX/specification#1058 · 1 comment · 0 reactions · 0 assignees ·
-
CDX 2.0 proposed core enhancement
CycloneDX/specification#1066 · 0 comments · 0 reactions · 0 assignees ·
-
breaking-changes proposed core enhancement request for comment RFC notice sent
CycloneDX/specification#1072 · 2 comments · 0 reactions · 1 assignee ·
-
defect documentation format: JSON
CycloneDX/specification#1076 · 1 comment · 0 reactions · 1 assignee ·
-
proposed core enhancement
CycloneDX/specification#1081 · 2 comments · 0 reactions · 0 assignees ·
-
cap: formulation CDX 2.0 defect
CycloneDX/specification#1083 · 0 comments · 0 reactions · 1 assignee ·
-
CDX 2.0 documentation
CycloneDX/specification#1085 · 0 comments · 0 reactions · 1 assignee ·
-
documentation
CycloneDX/specification#1086 · 0 comments · 0 reactions · 0 assignees ·
-
revisit formulations Opencap: formulation
CycloneDX/specification#1089 · 1 comment · 0 reactions · 1 assignee ·
-
chore
CycloneDX/specification#1094 · 0 comments · 0 reactions · 1 assignee ·
-
proposed core enhancement
CycloneDX/specification#1098 · 0 comments · 0 reactions · 0 assignees ·