dotnet-buildbom
0.1.1
dotnet tool install --global dotnet-buildbom --version 0.1.1
dotnet new tool-manifest
dotnet tool install --local dotnet-buildbom --version 0.1.1
#tool dotnet:?package=dotnet-buildbom&version=0.1.1
nuke :add-package dotnet-buildbom --version 0.1.1
buildbom
A CycloneDX SBOM from what your .NET build actually resolved and shipped — not from what the project files say.
buildbom reads the MSBuild binary log of a build or publish you already ran (or runs one for you), joins the NuGet
graph with the SDK's post-conflict item lists, decorates packages from the local .nuspec, and writes a CycloneDX BOM
whose shape is compatible with cyclonedx-dotnet — verified against
that project's own end-to-end suite (51 tests, 12 snapshots).
dotnet publish src/App -c Release -r linux-x64 -bl:sbom.binlog # your build, one flag added
dotnet buildbom sbom.binlog -o artifacts/ # ~1 s → artifacts/bom.xml
dotnet buildbom MySolution.slnx -o artifacts/ -F json # or let buildbom run the build
Why the build and not project.assets.json: the assets file does not know which package files the SDK drops at build
time, cannot see conditional/injected/CPM-evaluated references without a real evaluation, and trimming/AOT destroy the
evidence after publish. The research that established this, with a fixture built to break SBOM tools and three real
repositories, is in research/attachment-points.md.
Install
dotnet tool install -g dotnet-buildbom # from nuget.org, once published
dotnet pack src/BuildBom.Cli -o artifacts && dotnet tool install -g dotnet-buildbom --add-source artifacts # from source
Needs the .NET SDK 10 or later on the machine that runs the build; the tool itself rolls forward to any newer runtime.
Status
- Drop-in for
dotnet CycloneDXon SDK 10+ projects: same CLI names, same BOM shape (docs/cyclonedx-dotnet-compat.mdlists every kept/dropped feature and every deliberate difference — resolved edges instead of declared ranges, transitive-aware--exclude-dev, evaluated project version). - Not yet emitted: frameworks/runtime packs, raw
<Reference>DLLs, native assets, analyzers, deployment mode, publish-dir hashes. They are in the model; a--fullmode is the next step. - Not supported by design:
packages.configand non-SDK-style projects — refused with a clear message (exit 2) before anything is built; use cyclonedx-dotnet for those. SDK-style projects targeting .NET Framework work.
Contributing
Repository layout, build/test commands and the CI setup are in docs/architecture.md; where the
project stands and what comes next is in docs/status.md.
License
MIT — see LICENSE.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.1 | 111 | 9/13/2026 |