> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Output formats

> The raw, SPDX 2.3, and CycloneDX 1.7 formats that scanoss-cli writes, and how to convert SBOMs offline.

## Formats

```bash theme={null}
scanoss-cli scan ./my-project --api-key "$SCANOSS_API_KEY" --format raw       --output results.json
scanoss-cli scan ./my-project --api-key "$SCANOSS_API_KEY" --format spdx      --output sbom-spdx.json
scanoss-cli scan ./my-project --api-key "$SCANOSS_API_KEY" --format cyclonedx --output sbom-cdx.json
```

| Format | Notes |
| - | - |
| `raw` | **Default.** The neutral inventory: components tagged by `scope`, per-component layers inline, a flat vulnerabilities list, wrapped in a versioned envelope. Renders every `--include` layer. |
| `spdx` | SPDX 2.3. Drops `vulns`/`crypto`/`geo` layers. Multiple licences on a component are combined with `AND`. |
| `cyclonedx` | CycloneDX 1.7, with licences, evidence, and vulnerabilities. Drops `crypto`/`geo` layers. |

The CLI merges components with the same identity, meaning the same PURL and version, into one. A
package listed in both `package.json` and `package-lock.json`, or one that is both detected and
declared, appears once. Different versions of the same PURL stay separate.

## Converting formats offline

The `sbom` command converts between formats without contacting the API. It detects the input
format from the file's content:

```bash theme={null}
# SPDX -> CycloneDX
scanoss-cli sbom bom.spdx.json --format cyclonedx --output bom.cdx.json

# CycloneDX -> SPDX
scanoss-cli sbom bom.cdx.json --format spdx --output bom.spdx.json

# scanoss raw result -> CycloneDX or SPDX
scanoss-cli sbom results.json --format cyclonedx --output bom.cdx.json
```

Conversion is **best-effort**. The CLI drops any data the target format can't represent and prints
a warning. For example, SPDX 2.3 has no vulnerability model, so converting to `spdx` leaves out the
vulnerabilities.

`sbom` takes `-f, --format` (`cyclonedx` or `spdx`) and `-o, --output`.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.