# CMake & CPS

**URL:** https://discourse.cmake.org/t/cmake-cps/11224
**Category:** Community
**Created:** [July 11, 2024, 2:17pm UTC](https://discourse.cmake.org/t/cmake-cps/11224 "2024-07-11T14:17:21Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Oodini](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/o/db5fbb/32.png) [@Oodini](https://discourse.cmake.org/u/Oodini)
#### Post date: [July 11, 2024, 2:17pm UTC](https://discourse.cmake.org/t/cmake-cps/11224/1 "2024-07-11T14:17:21Z")

</div>

Hello,

The company where I work will have to produce SBOM for its software. I discoved the [CPS initiative](https://cps-org.github.io/cps/overview.html).

Is it already possible to use it with CMake in order to produce the SBOM by some other tool ?

---

<div class="post-metadata">

### Author: ![craig.scott](https://discourse.cmake.org/user_avatar/discourse.cmake.org/craig.scott/32/20_2.png) [@craig.scott](https://discourse.cmake.org/u/craig.scott)
#### Post date: [July 11, 2024, 10:00pm UTC](https://discourse.cmake.org/t/cmake-cps/11224/2 "2024-07-11T22:00:53Z")

</div>

Not that I’m aware of.

---

<div class="post-metadata">

### Author: ![alcroito](https://discourse.cmake.org/user_avatar/discourse.cmake.org/alcroito/32/186_2.png) [@alcroito](https://discourse.cmake.org/u/alcroito)
#### Post date: [July 18, 2024, 9:24am UTC](https://discourse.cmake.org/t/cmake-cps/11224/3 "2024-07-18T09:24:34Z")

</div>

I’m not sure how you intended to use CPS for creating an SBOM, but there are 3rd party projects that help with creating an SBOM.

> **[GitHub - DEMCON/cmake-sbom: Guided SBOM generation from CMake](https://github.com/DEMCON/cmake-sbom)**
>
> Guided SBOM generation from CMake. Contribute to DEMCON/cmake-sbom development by creating an account on GitHub.

> **[GitHub - swinslow/cmake-spdx: Create SPDX documents automatically with CMake...](https://github.com/swinslow/cmake-spdx)**
>
> Create SPDX documents automatically with CMake build info - swinslow/cmake-spdx

Qt, which uses CMake, also recently added support for generating an SBOM. You could use it as inspiration, but it was based on the approach in DEMCON/cmake-sbom  
[https://codereview.qt-project.org/c/qt/qtbase/+/546923](https://codereview.qt-project.org/c/qt/qtbase/+/546923)

---

<div class="post-metadata">

### Author: ![Oodini](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/o/db5fbb/32.png) [@Oodini](https://discourse.cmake.org/u/Oodini)
#### Post date: [July 18, 2024, 10:00am UTC](https://discourse.cmake.org/t/cmake-cps/11224/4 "2024-07-18T10:00:34Z")

</div>

> [@alcroito](#):
>
> I’m not sure how you intended to use CPS for creating an SBOM

Well, it appears that CPS could contain the minimal info to create the SBOM. So it should be possible with some scripting.

> [@alcroito](#):
>
> there are 3rd party projects that help with creating an SBOM

Thanks ! They’re will be useful until CPS is specified and implemented.
