{"id":20617807,"url":"https://github.com/cyclonedx/cyclonedx-php-library","last_synced_at":"2026-02-16T12:25:49.717Z","repository":{"id":38419980,"uuid":"405605507","full_name":"CycloneDX/cyclonedx-php-library","owner":"CycloneDX","description":"PHP Implementation of OWASP CycloneDX Bill of Materials (BOM)","archived":false,"fork":false,"pushed_at":"2025-03-02T09:36:59.000Z","size":2562,"stargazers_count":8,"open_issues_count":15,"forks_count":0,"subscribers_count":5,"default_branch":"master","last_synced_at":"2025-03-05T09:03:14.618Z","etag":null,"topics":["bill-of-materials","bom","cyclonedx","hacktoberfest","library","mbom","obom","owasp","php","saasbom","sbom","software-bill-of-materials","software-library","spdx","vex"],"latest_commit_sha":null,"homepage":"https://cyclonedx.org/","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/CycloneDX.png","metadata":{"files":{"readme":"README.md","changelog":"HISTORY.md","contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"custom":["https://owasp.org/donate/?reponame=www-project-cyclonedx\u0026title=OWASP+CycloneDX"]}},"created_at":"2021-09-12T10:00:04.000Z","updated_at":"2025-03-02T09:36:55.000Z","dependencies_parsed_at":"2023-12-23T12:21:56.475Z","dependency_job_id":"c7edd9bb-9950-4ef1-a683-89d64789fa95","html_url":"https://github.com/CycloneDX/cyclonedx-php-library","commit_stats":{"total_commits":346,"total_committers":2,"mean_commits":173.0,"dds":0.2890173410404624,"last_synced_commit":"72a5823a5e5f10be65cc80188894e08058718d7c"},"previous_names":[],"tags_count":39,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CycloneDX%2Fcyclonedx-php-library","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CycloneDX%2Fcyclonedx-php-library/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CycloneDX%2Fcyclonedx-php-library/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CycloneDX%2Fcyclonedx-php-library/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/CycloneDX","download_url":"https://codeload.github.com/CycloneDX/cyclonedx-php-library/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":249061650,"owners_count":21206540,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bill-of-materials","bom","cyclonedx","hacktoberfest","library","mbom","obom","owasp","php","saasbom","sbom","software-bill-of-materials","software-library","spdx","vex"],"created_at":"2024-11-16T12:06:02.053Z","updated_at":"2026-01-07T15:15:29.347Z","avatar_url":"https://github.com/CycloneDX.png","language":"PHP","funding_links":["https://owasp.org/donate/?reponame=www-project-cyclonedx\u0026title=OWASP+CycloneDX"],"categories":[],"sub_categories":[],"readme":"# CycloneDX PHP Library\n\n[![shield_packagist-version]][link_packagist]\n[![shield_rtfd]][link_rtfd]\n[![shield_gh-workflow-test]][link_gh-workflow-test]\n[![shield_coverage]][link_codacy]\n[![shield_shepherd]][link_shepherd]\n[![shield_ossf-best-practices]][link_ossf-best-practices]\n[![shield_license]][license_file]  \n[![shield_website]][link_website]\n[![shield_slack]][link_slack]\n[![shield_groups]][link_discussion]\n[![shield_twitter-follow]][link_twitter]\n\n----\n\nWork with [CycloneDX] documents.  \nOWASP CycloneDX is a full-stack Bill of Materials (BOM) standard\nthat provides advanced supply chain capabilities for cyber risk reduction.\n\n\u003e [!NOTE]  \n\u003e This package is a software library not intended for standalone use.  \n\u003e For generating Software Bill of Materials (SBOM), check out [CycloneDX PHP Composer Plugin](https://github.com/CycloneDX/cyclonedx-php-composer).\n\n## Responsibilities\n\n* Provide a general purpose _php_-implementation of [_CycloneDX_][CycloneDX].\n* Provide [_phpDoc3_](https://phpdoc.org/)- \u0026 [_psalm_](https://psalm.dev/)-compatible annotations for said implementation,\n  so developers and dev-tools can rely on it.\n* Provide data models to work with _CycloneDX_.\n* Provide a JSON- and an XML-normalizer, that...\n  * supports all shipped data models.\n  * respects any injected [_CycloneDX_ Specification][CycloneDX-spec] and generates valid output according to it.\n  * can prepare data structures for JSON- and XML-serialization.\n* Serialization:\n  * Provide a JSON-serializer.\n  * Provide an XML-serializer.\n* Validation against _CycloneDX_ Specification:\n  * Provide a JSON-validator.\n  * Provide an XML-validator.\n* Provide [_composer_-based autoloading](https://getcomposer.org/doc/01-basic-usage.md#autoloading) for downstream usage.\n\n## Capabilities\n\n* Enums for the following use cases:\n  * `ComponentType`\n  * `ExternalReferenceType`\n  * `HashAlgorithm`\n  * `LicenseAcknowledgement`\n* Data models for the following use cases:\n  * `Bom`\n  * `BomRef`, `BomRefRepository`\n  * `Component`, `ComponentRepository`, `ComponentEvidence`\n  * `ExternalReference`, `ExternalReferenceRepository`\n  * `HashDictionary`\n  * `LicenseExpression`, `NamedLicense`, `SpdxLicense`, `LicenseRepository`\n  * `Metadata`\n  * `Property`, `PropertyRepository`\n  * `Tool`, `ToolRepository`\n* Utilities for the following use cases:\n  * Generate valid random SerialNumbers for `Bom.serialNumber`\n* Factories for the following use cases:\n  * Create data models from any license descriptor string\n* Implementation of the [_CycloneDX_ Specification][CycloneDX-spec] for the following versions:\n  * `1.7`\n  * `1.6`\n  * `1.5`\n  * `1.4`\n  * `1.3`\n  * `1.2`\n  * `1.1`\n* Normalizers that convert data models to JSON structures\n* Normalizers that convert data models to  XML structures\n* Serializer that converts `Bom` data models to JSON string\n* Serializer that converts `Bom` data models to  XML string\n* Validator that checks JSON against _CycloneDX_ Specification\n* Validator that checks  XML against _CycloneDX_ Specification\n\n## Installation\n\nInstall via composer:\n\n```shell\ncomposer require cyclonedx/cyclonedx-library\n```\n\n## Usage\n\nSee extended [examples].\n\n```php\n$bom = new \\CycloneDX\\Core\\Models\\Bom();\n$bom-\u003egetComponents()-\u003eaddItems(\n    new \\CycloneDX\\Core\\Models\\Component(\n        \\CycloneDX\\Core\\Enums\\ComponentType::Library,\n        'myComponent'\n    )\n);\n```\n\n## API Documentation\n\nWe ship code annotations, so that your IDE and tools may pick up the documentation when you use this library downstream.\n\nThere are also pre-rendered documentations hosted on [readthedocs][link_rtfd].\n\nAdditionally, there is a prepared config for [_phpDoc3_](https://docs.phpdoc.org/guide/getting-started/index.html)\nthat you can use to generate the docs for yourself.\n\n## Conflicts\n\nDue to the fact that this library was split out of [`/src/Core` of cyclonedx-php-composer (346e6200fb2f5086061b15c2ee44f540893ce97d)](https://github.com/CycloneDX/cyclonedx-php-composer/tree/346e6200fb2f5086061b15c2ee44f540893ce97d/src/Core)\nit will conflict with its original source: `cyclonedx/cyclonedx-php-composer:\u003c3.5`.\n\n## Contributing\n\nFeel free to open issues, bug reports or pull requests.  \nSee the [CONTRIBUTING][contributing_file] file for details.\n\n## License\n\nPermission to modify and redistribute is granted under the terms of the Apache 2.0 license.  \nSee the [LICENSE][license_file] file for the full license.\n\n[CycloneDX]: https://cyclonedx.org/\n[CycloneDX-spec]: https://github.com/CycloneDX/specification/tree/master#readme\n\n[license_file]: https://github.com/CycloneDX/cyclonedx-php-library/blob/master/LICENSE\n[contributing_file]: https://github.com/CycloneDX/cyclonedx-php-library/blob/master/CONTRIBUTING.md\n[examples]: https://github.com/CycloneDX/cyclonedx-php-library/tree/master/examples\n[link_rtfd]: https://cyclonedx-php-library.readthedocs.io\n\n[shield_packagist-version]: https://img.shields.io/packagist/v/cyclonedx/cyclonedx-library?logo=Packagist\u0026logoColor=white \"packagist\"\n[shield_rtfd]: https://img.shields.io/readthedocs/cyclonedx-php-library?logo=readthedocs\u0026logoColor=white \"Read the Docs\"\n[shield_gh-workflow-test]: https://img.shields.io/github/actions/workflow/status/CycloneDX/cyclonedx-php-library/php.yml?branch=master\u0026logo=GitHub\u0026logoColor=white \"build\"\n[shield_coverage]: https://img.shields.io/codacy/coverage/7e5610bee31a4c99b1b8efb0eeab9e73?logo=Codacy\u0026logoColor=white \"test coverage\"\n[shield_shepherd]: https://shepherd.dev/github/CycloneDX/cyclonedx-php-library/coverage.svg \"type coverage\"\n[shield_ossf-best-practices]: https://img.shields.io/cii/percentage/7955?label=OpenSSF%20best%20practices \"OpenSSF best practices\"\n[shield_license]: https://img.shields.io/github/license/CycloneDX/cyclonedx-php-library?logo=open%20source%20initiative\u0026logoColor=white \"license\"\n[shield_website]: https://img.shields.io/badge/https://-cyclonedx.org-blue.svg \"homepage\"\n[shield_slack]: https://img.shields.io/badge/slack-join-blue?logo=Slack\u0026logoColor=white \"slack join\"\n[shield_groups]: https://img.shields.io/badge/discussion-groups.io-blue.svg \"groups discussion\"\n[shield_twitter-follow]: https://img.shields.io/badge/Twitter-follow-blue?logo=Twitter\u0026logoColor=white \"twitter follow\"\n[link_packagist]: https://packagist.org/packages/cyclonedx/cyclonedx-library\n[link_gh-workflow-test]: https://github.com/CycloneDX/cyclonedx-php-library/actions/workflows/php.yml?query=branch%3Amaster\n[link_codacy]: https://app.codacy.com/gh/CycloneDX/cyclonedx-php-library\n[link_shepherd]: https://shepherd.dev/github/CycloneDX/cyclonedx-php-library\n[link_ossf-best-practices]: https://www.bestpractices.dev/projects/7955\n[link_website]: https://cyclonedx.org/\n[link_slack]: https://cyclonedx.org/slack/invite\n[link_discussion]: https://groups.io/g/CycloneDX\n[link_twitter]: https://twitter.com/CycloneDX_Spec\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcyclonedx%2Fcyclonedx-php-library","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcyclonedx%2Fcyclonedx-php-library","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcyclonedx%2Fcyclonedx-php-library/lists"}