@cyclonedx/cdxgen
Creates CycloneDX Software Bill of Materials (SBOM) from source or container image
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:credential-dir-access | AI (semgrep): cdxgen scans filesystem for SBOM generation; reading docker config paths is expected behavior. | ai | |
| semgrep | semgrep:dll-hijacking-commands | AI (semgrep): lolbas.js is a reference list of known LOLBins for security analysis, not actual DLL hijacking. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): SBOM generator needs full env context to invoke build tools; spreading process.env is intentional. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Appears in a test fixture for directory traversal safety checks, not production credential harvesting. | ai | |
| semgrep | semgrep:dll-injection-apis | AI (semgrep): Reference to LD_PRELOAD etc. is in an env-var allowlist/denylist for SBOM generation, not injection code. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Enumerating env vars to capture build environment metadata is core to SBOM formulation. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): toBase64() is a utility for encoding hashes/digests in SBOM output, not payload obfuscation. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP appears in a test fixture for IRI parsing, not a live network request. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decoding a user-supplied private key env var for SBOM signing is documented and expected functionality. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 12.8.2 | 29 / 5 | |
| 12.8.1 | 29 / 5 | |
| 12.8.0 | 29 / 5 | |
| 12.7.1 | 29 / 5 | |
| 12.7.0 | 35 / 5 | |
| 12.6.0 | 35 / 5 | |
| 12.5.1 | 35 / 5 | |
| 12.5.0 | 35 / 5 | |
| 12.4.4 | 36 / 5 | |
| 12.4.3 | 36 / 5 | |
| 12.4.2 | 36 / 5 | |
| 12.4.1 | 36 / 5 | |
| 12.3.3 | 36 / 5 |
v12.8.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.4.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.