Standalone Maven plugin that produces a CycloneDX SBOM only. It
enumerates dependencies via whatever mechanism is native to Maven: the
resolved project dependency graph, the resolved plugin/build-tooling
graph, and the BOM import declarations - then writes them out as a
CycloneDX SBOM. No Gradle awareness, and no vendor/EOL/CVE annotation
logic lives here; this module has no dependency on scanner-core or any
other module in this reactor.
Latest Versions
1 versions โ| Version | Vulnerabilities | Usages | Date | |
|---|---|---|---|---|
0.0.x | 0.0.1 |
0
| Aug 04, 2026 |