05/12/2026
CycloneDX SBOM files for DevExpress .NET NuGet packages are now available in preview. If you're building apps that ship to EU customers, the Cyber Resilience Act will require a Software Bill of Materials as part of your conformity documentation. Our SBOMs cover first-party and third-party dependencies, include dependency graphs, and work with standard analysis tools like Dependency-Track, Trivy, and Grype. Current scope is our v25.2.6 .NET packages across Blazor, WinForms, WPF, ASP.NET Core, and more. We're looking for feedback from developers working on compliance and supply chain security before broadening coverage. Details and survey access in the post.
If you ship apps to customers in the EU, the Cyber Resilience Act (CRA) will require an SBOM as part of your conformity documentation. SBOM generation and CRA compliance are top priorities for DevExpress, and CycloneDX SBOM files for our .NET NuGet packages are now available as a preview