Kai Ole Hartwig

name of the term: SBOM
descriptions of the term:

Definition

Definition. An SBOM (Software Bill of Materials) is a machine-readable inventory of every component in a piece of software. It lists libraries, versions and dependencies. It answers one question: what exactly is inside this application? Common formats are CycloneDX and SPDX.

Why it matters. When a vulnerability surfaces in a widely used library, an SBOM shows within minutes which systems are affected. Without it, that answer takes manual research. For mid-sized platforms the SBOM is a practical core tool of supply chain security. Ideally it is generated automatically in the build.

Related. SLSA, Supply Chain Security, DevSecOps, Software Provenance

Type of term: acronym
Language of the term (2 char ISO code): en
Back