rustio rustio.net
60

cyclonedx-bom

v0.8.1 Growing

CycloneDX Software Bill of Materials Library

Apache-2.0 Edition 2021 MSRV 1.85.0
EncodingParser implementations #dependencies#components#bom#owasp#sbom

Quick Verdict

  • โœ“Actively maintained (updated 67d ago)
  • !Pre-1.0: API may have breaking changes
  • โœ“Trusted by 220 crates
  • โœ“Permissive license (Apache-2.0)

Security

Checking security advisories...
Downloads
1.2M
Dependents
220
Releases
19
Size
189KB

Deep Insights

๐Ÿ“Š
Steady growth

247.5K downloads in the last 30 days (8.3K/day), up 14% from the previous period.

๐Ÿ”—
Moderate adoption

220 crates depend on cyclonedx-bom. Reasonable ecosystem adoption, though not yet a core dependency.

๐Ÿ”ฌ
Pre-1.0 for over a year

Despite being 6+ years old, cyclonedx-bom hasn't reached 1.0 yet. Expect potential API changes between versions.

๐ŸŒŸ
Used by top crates

Notable dependents include cargo-cyclonedx, libcnb, sbom-walker, uv-resolver, hipcheck. When high-quality crates choose cyclonedx-bom, it's a strong quality signal.

Health Breakdown

Maintenance 14/25

Recency, release consistency, active ratio

Quality 11/25

Yanked ratio, deps, size, maturity, features

Community 16/20

Reverse deps, ownership, ecosystem

Popularity 7/15

Downloads, momentum, growth trend

Documentation 12/15

Docs, repo, license, metadata

Download Trend

Daily downloads ยท last 90 days
7K/day avg+34%
05K10K2/263/164/34/215/95/26

Top Dependents

Version Adoption

v0.8.0
63%
v0.8.1
27%
v0.6.2
4%
v0.7.0
3%
v0.4.3
2%

Release Timeline

10 releasessince 2022
J
F
M
A
M
J
J
A
S
O
N
D
2022
1
2023
2
2024
6
2025
2026
1
Less
More

README

Loading README...

Maintainers

Dependencies
18
direct dependencies
Dependents
220
crates depend on cyclonedx-bom

Similar Crates