An SBOM is a tool output, not a fact about your software
Two papers appeared on arXiv in September that describe, from opposite ends, a pipeline control I have shipped many times. The first, from Inria and ANSSI, ran three SBOM generators over the same 3,326 repositories and found that two of them miss more than half of the dependencies in JavaScript projects. The second ran 1,920 trials of AI coding assistants installing software and found that they opened an SBOM, signature or attestation before installing in 0.5% of trials and verified one in none. My position: an SBOM generated in CI is evidence about the tool you ran, at the version you ran it,
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in