dotnet-buildbom 0.1.1

dotnet tool install --global dotnet-buildbom --version 0.1.1
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local dotnet-buildbom --version 0.1.1
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=dotnet-buildbom&version=0.1.1
                    
nuke :add-package dotnet-buildbom --version 0.1.1
                    

buildbom

CI

A CycloneDX SBOM from what your .NET build actually resolved and shipped — not from what the project files say.

buildbom reads the MSBuild binary log of a build or publish you already ran (or runs one for you), joins the NuGet graph with the SDK's post-conflict item lists, decorates packages from the local .nuspec, and writes a CycloneDX BOM whose shape is compatible with cyclonedx-dotnet — verified against that project's own end-to-end suite (51 tests, 12 snapshots).

dotnet publish src/App -c Release -r linux-x64 -bl:sbom.binlog      # your build, one flag added
dotnet buildbom sbom.binlog -o artifacts/                            # ~1 s → artifacts/bom.xml

dotnet buildbom MySolution.slnx -o artifacts/ -F json                # or let buildbom run the build

Why the build and not project.assets.json: the assets file does not know which package files the SDK drops at build time, cannot see conditional/injected/CPM-evaluated references without a real evaluation, and trimming/AOT destroy the evidence after publish. The research that established this, with a fixture built to break SBOM tools and three real repositories, is in research/attachment-points.md.

Install

dotnet tool install -g dotnet-buildbom                              # from nuget.org, once published
dotnet pack src/BuildBom.Cli -o artifacts && dotnet tool install -g dotnet-buildbom --add-source artifacts   # from source

Needs the .NET SDK 10 or later on the machine that runs the build; the tool itself rolls forward to any newer runtime.

Status

  • Drop-in for dotnet CycloneDX on SDK 10+ projects: same CLI names, same BOM shape (docs/cyclonedx-dotnet-compat.md lists every kept/dropped feature and every deliberate difference — resolved edges instead of declared ranges, transitive-aware --exclude-dev, evaluated project version).
  • Not yet emitted: frameworks/runtime packs, raw <Reference> DLLs, native assets, analyzers, deployment mode, publish-dir hashes. They are in the model; a --full mode is the next step.
  • Not supported by design: packages.config and non-SDK-style projects — refused with a clear message (exit 2) before anything is built; use cyclonedx-dotnet for those. SDK-style projects targeting .NET Framework work.

Contributing

Repository layout, build/test commands and the CI setup are in docs/architecture.md; where the project stands and what comes next is in docs/status.md.

License

MIT — see LICENSE.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
0.1.1 111 9/13/2026