BOMTOOL(1) General Commands Manual BOMTOOL(1)

bomtoola tool for generating SPDX-based software bills of material

bomtool [options] module ...

bomtool is a program which generates a textual SPDX 2.0 software bill of materials (SBOM) for a given set of pkg-config modules. The output of this tool can then be translated into other SBOM formats as necessary.

The options are as follows:

Print the version number, the Copyright notice, and the license of the bomtool program to standard output and exit. Most other options and all command line arguments are ignored.
Print the version number of the bomtool program to standard output and exit. Most other options and all command line arguments are ignored.
=varname=value
Define varname as value. Variables are used in query output, and some modules' results may change based on the presence of a variable definition.
time
Use time as the value of the Created field in the generated SBOM instead of the current time. SPDX recommends using an ISO 8601-formatted time, which is: YYYY-MM-DDThh:mm:ssZ. This takes precedence over the SOURCE_DATE_EPOCH environment variable.
file
Write the generated SBOM to file instead of standard output.

If set, print debugging messages to stderr.
If set, ignore Conflicts rules in modules. Has the same effect as the --ignore-conflicts option in pkgconf(1)
A colon-separated list of low-priority directories where pc(5) files are looked up. The module search path is constructed by appending this list to PKG_CONFIG_PATH, which enjoys higher priority. If PKG_CONFIG_LIBDIR is not defined, the default list compiled into the bomtool program from the PKG_DEFAULT_PATH preprocessor macro is appended instead. If PKG_CONFIG_LIBDIR is defined but empty, nothing is appended.
Impose a limit on the allowed depth in the dependency graph.
A colon-separated list of high-priority directories where pc(5) files are looked up.
Colon-separated list of pc(5) files which are loaded before any other pkg-config files. These packages are given highest priority over any other pc(5) files that would otherwise provide a given package.
If set, and the --creation-time option is not given, the Created field in the generated SBOM is derived from this UNIX timestamp instead of the current time, allowing for reproducible SBOM generation.

The bomtool utility exits 0 on success, and >0 if an error occurs.

Generating an SBOM for the package named foo:

$ bomtool foo
SPDXVersion: SPDX-2.2
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: SBOM-SPDX-fooC641.2.3
Creator: Tool: bomtool
[...]

pc(5), pkgconf(1)

June 24, 2026 Linux 6.12.107+deb13-amd64