← Home

@cyclonedx/cdxgen

Creates CycloneDX Software Bill of Materials (SBOM) from source or container image

13
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sspringetteoftedalcoderpatroscyclonedx-automationjkowalleck

Keywords

sbombominventoryspdxpackage-urlpurlowaspcomponentdependencyappsecscrm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:credential-dir-access AI (semgrep): cdxgen scans filesystem for SBOM generation; reading docker config paths is expected behavior. ai
semgrep semgrep:dll-hijacking-commands AI (semgrep): lolbas.js is a reference list of known LOLBins for security analysis, not actual DLL hijacking. ai
semgrep semgrep:env-spread AI (semgrep): SBOM generator needs full env context to invoke build tools; spreading process.env is intentional. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Appears in a test fixture for directory traversal safety checks, not production credential harvesting. ai
semgrep semgrep:dll-injection-apis AI (semgrep): Reference to LD_PRELOAD etc. is in an env-var allowlist/denylist for SBOM generation, not injection code. ai
semgrep semgrep:env-bulk-read AI (semgrep): Enumerating env vars to capture build environment metadata is core to SBOM formulation. ai
semgrep semgrep:hex-decode AI (semgrep): toBase64() is a utility for encoding hashes/digests in SBOM output, not payload obfuscation. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP appears in a test fixture for IRI parsing, not a live network request. ai
semgrep semgrep:base64-decode AI (semgrep): Decoding a user-supplied private key env var for SBOM signing is documented and expected functionality. ai

Versions (showing 13 of 13)

Version Deps Published
12.8.2 29 / 5
12.8.1 29 / 5
12.8.0 29 / 5
12.7.1 29 / 5
12.7.0 35 / 5
12.6.0 35 / 5
12.5.1 35 / 5
12.5.0 35 / 5
12.4.4 36 / 5
12.4.3 36 / 5
12.4.2 36 / 5
12.4.1 36 / 5
12.3.3 36 / 5

v12.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.