CMAKE_INSTALL_SBOM_FORMATSΒΆ
Added in version 4.5.
Enable automatic generation and installation of Software Bill of Materials (SBOM) documents for the project's install export sets.
Set this variable in the top-level directory, or in the cache, to spdx
to generate an SBOM for each export set created by install(TARGETS)
with the EXPORT option. Export sets already covered by an explicit
install(SBOM) call are skipped.
Each automatically generated SBOM uses the export set name as its package
name and the top-level project name to obtain project metadata. It is
installed under <libdir>/sbom/<export-name>, where <libdir> is the
value of CMAKE_INSTALL_LIBDIR, or lib if that variable is unset or
empty.
The value uses the same format names as the FORMAT option of
install(SBOM) and export(SBOM). Currently, spdx and
spdx-3.0+json are supported and select SPDX JSON output.
For example, a package distributor can enable SBOM installation without modifying a project's build scripts:
cmake -S . -B build -DCMAKE_INSTALL_SBOM_FORMATS=spdx
cmake --build build
cmake --install build
Projects that need to customize SBOM metadata, format, or destination should
use install(SBOM) directly.