| ▲ | Khaine 7 hours ago | |||||||
SBOMs are a solution intended to help solve a couple of problems: 1) help identify and remediate software that has been built with vulnerable packages (think log4j). 2) help protect against supply chain compromise as the SBOM contains hashes that allow packages to be verified | ||||||||
| ▲ | pacificpendant 3 hours ago | parent | next [-] | |||||||
https://www.ntia.gov/sites/default/files/publications/sbom_m... Depending on who you ask an SBOM might not need a hash. NTIA only recommend a hash. | ||||||||
| ▲ | ozim 5 hours ago | parent | prev [-] | |||||||
You forgot about the important one SBOMs are created with thought about sharing them with third parties like your customers - lock files not. | ||||||||
| ||||||||