Functionality and DataModels of OWASP CycloneDX for Python
-
Updated
Sep 29, 2026 - Python
Functionality and DataModels of OWASP CycloneDX for Python
sbomify is a product security artifact hub and a trust center.
BF-CBOM: Your Best Friend for Generating, Understanding, and Comparing Cryptography Bills of Material (CBOMs)
Open-source TLS & SSH post-quantum cryptography scanner that generates a Cryptographic Bill of Materials (CBOM) aligned to NIST IR 8547.
Scans code across 11 languages for cryptography that quantum computers will break, scores the risk 0-100, and maps every finding to its NIST FIPS 203/204/205 replacement. Published on PyPI (quantumsafe-scan).
Developer-native scanner for quantum-vulnerable cryptography. Runs as a GitHub Action, produces inline PR annotations.
Runtime Cryptography Bill of Materials (CBOM) extraction via eBPF/bpftrace, generating CycloneDX 1.6 CBOMs and evaluation charts for OpenSSL-based apps.
Open-source tools for post-quantum cryptography readiness assessment
Cyber Reasoning & Post-Quantum Security Framework. Autonomous binary analysis, NIST FIPS 203 ML-KEM, Microsoft Z3 SMT solver, and microarchitectural forensics.
PQC-MAT ships VECTOR — a post-quantum cryptography migration toolkit with CodeQL-based crypto discovery (Code), TLS/SSH cipher & KEM inventory (Network), CBOM quantum risk scoring against NIST/BSI/ANSSI standards (Score), and a browser-based scan & review interface (GUI).
Find the cryptography quantum computers will break, export a CycloneDX CBOM, and map it to NIST, US federal, CNSA 2.0, NCSC and EU deadlines.
Inventario criptográfico y priorización de la migración post-cuántica con políticas europeas (UE / CCN)
Crypto-discovery and crypto-agility audit toolkit per il mercato italiano (PA, SMB, financial sector). NIS2/DORA/AgID-aware. AGPL-3.0.
Signed static audits of what a codebase actually does: network egress, crypto inventory, key provenance, and declared dependencies. No runtime deps. Re-run it yourself.
Post-quantum cryptographic risk scanner: CBOM (CycloneDX 1.6) + SARIF + policy gates for Python and Go codebases
Synthetic X.509 fixtures and reproducible checks for CycloneDX certificate fingerprint semantics
Open-source post-quantum cryptography inventory: find where systems rely on quantum-vulnerable cryptography and plan the migration. CycloneDX 1.6 CBOM output and an accessible HTML report.
Local cryptographic asset inventory CLI emitting CycloneDX 1.7 CBOM. By Qtonic Quantum.
Cryptographic inventory aggregation and mandate reporting. Consumes existing scanners, emits the filings you owe. Not another scanner.
To associate your repository with the cbom topic, visit your repo's landing page and select "manage topics."