Posts

๐ What Makes Signing SBOMs Hard in Practice?
Everyone agrees SBOMs should be signed. But actually doing it? Thatโs where things get messy. Letโs t...

Your SBOM Can Be Hacked ๐ฆ๐
Yes, even the one you just generated. An SBOM (Software Bill of Materials) is supposed to bring transparency and trust t...

Why SBOMs Are Not One-and-Done ๐ฆ๐
โ Youโve generated an SBOM. Congratulations! But hereโs the truth. An SBOM is not a report you create once a...

๐ช๐ต๐ผ ๐ฎ๐ฐ๐๐๐ฎ๐น๐น๐ ๐ฏ๐๐ถ๐น๐ฑ๐ ๐ฆ๐๐ข๐ ๐? ๐๐ป๐ฑ ๐๐ต๐ผ ๐ป๐ฒ๐ฒ๐ฑ๐ ๐๐ต๐ฒ๐บ? ๐ค๐
SBOMs are a critical tool for understanding your software supply chain. But not everyone touches an SBOM the same way. T...

What's Inside an SBOM? ๐ง
(Image sourced from OWASP CycloneDX SBOM/xBOM Standard) - https://cyclo...

Not all BOMs are created equal ๐
In the physical world, a Bill of Materials (BOM) is straightforward: ๐ฉ You list the parts ๐ญ You know the ...