cdxgen — генерация SBOM и аудит зависимостей

★ 6.9 · devops

cdxgen is a Claude Code skill that runs OWASP cdxgen, a polyglot CLI tool for generating CycloneDX Bill-of-Materials documents — SBOM, HBOM, CBOM, OBOM, SaaSBOM, VDR, and CDXA — for source code, containers, VMs, and live operating systems. It supports CycloneDX spec versions 1.4–1.7 and includes a native JSON Signature Format implementation with granular component-level signatures, parallel Multi-Signatures, and sequential Signature Chains. When the optional `@cdxgen/cdxgen-plugins-bin` package is present, container and rootfs scans are enriched with Trivy/osquery metadata, GTFOBins runtime context, and Go Evinse semantic evidence via the golem helper. Security engineers and DevOps teams use it for dependency inventory, license resolution, Dependency-Track export, and predictive compromise audits of npm or PyPI packages with `cdx-audit`.