Definition. An SBOM (Software Bill of Materials) is a machine-readable inventory of every component in a piece of software. It lists libraries, versions and dependencies. It answers one question: what exactly is inside this application? Common formats are CycloneDX and SPDX.
Why it matters. When a vulnerability surfaces in a widely used library, an SBOM shows within minutes which systems are affected. Without it, that answer takes manual research. For mid-sized platforms the SBOM is a practical core tool of supply chain security. Ideally it is generated automatically in the build.
Related. SLSA, Supply Chain Security, DevSecOps, Software Provenance