For some background, checkout out this old post, which is about its sibling Mix task for Elixir projects. For usage instructions please refer to the README file over at GitHub.
This new version should work on OTP 25, but it no longer supports OTP <21.
CycloneDX is a standardised format for specifying (third party) dependencies of software projects. Such a file can be used for verifying license compliance, checking for known vulnerabilities, or as part of a product specification between supplier and client.