CLI utility to download public CycloneDX SBOMs from Maven Central
go install -v github.com/nscuro/cdx-central@latest
Usage of cdx-central:
-concurrency int
How many artifacts to process concurrently (default 5)
-min-components int
Minimum number of components in an SBOM (default 10)
-output string
Output directory (default ".")
Note
Currently only the SBOM for each artifact's latest version will be downloaded.
mkdir -p sboms
cdx-central -min-components 50 -output ./sboms