cdxgen — генерация SBOM и аудит зависимостей
★ 6.9 · devops
cdxgen is a Claude Code skill that runs OWASP cdxgen, a polyglot CLI tool for generating CycloneDX Bill-of-Materials documents — SBOM, HBOM, CBOM, OBOM, SaaSBOM, VDR, and CDXA — for source code, containers, VMs, and live operating systems. It supports CycloneDX spec versions 1.4–1.7 and includes a native JSON Signature Format implementation with granular component-level signatures, parallel Multi-Signatures, and sequential Signature Chains. When the optional `@cdxgen/cdxgen-plugins-bin` package is present, container and rootfs scans are enriched with Trivy/osquery metadata, GTFOBins runtime context, and Go Evinse semantic evidence via the golem helper. Security engineers and DevOps teams use it for dependency inventory, license resolution, Dependency-Track export, and predictive compromise audits of npm or PyPI packages with `cdx-audit`.
- #sbom
- #cyclonedx
- #bom-generation
- #container-scanning
- #dependency-analysis
- #security