Dropping the SBOM
The US government and others have identified a tool they consider essential in the fight against open source code vulnerabilities: the Software Bill of Materials (SBOM). A recent executive order means you won’t supply software for the US government without an SBOM, and other countries are following suit. So, what is an SBOM, and what does it take to create one? And is more needed to secure open source supply chains?
Report Snap Shot
- The software supply chain attack landscape
- Where SBOM compliance fits
- Thinking strategically beyond SBOMs
- The need for a unified, collaborative approach