Software bill of materials
A software bill of materials is a machine-readable inventory of every component and dependency contained in a piece of software, including versions.
What is software bill of materials?
A software bill of materials is a machine-readable inventory of every component and dependency contained in a piece of software, including versions.
Plain and technical
An SBOM lists everything inside your application (every library, every operating system package), so when a vulnerability is announced you can immediately tell whether you are affected.
An SBOM is typically expressed in SPDX or CycloneDX format and generated at build time, capturing direct and transitive dependencies with their versions and licences. Its operational value is query speed: with an SBOM index, identifying affected services after a disclosure is a lookup rather than a rescan of the estate.
What it looks like in practice
Nearby vocabulary
Vulnerability management
Vulnerability management is the continuous process of identifying security weaknesses, ranking them by real risk, fixing them and verifying the fix.
Containerization
Containerization packages an application together with its dependencies into an image that runs identically on any machine with a compatible container runtime.
DevSecOps
DevSecOps is the practice of integrating security verification into the software delivery process rather than applying it as a separate review at the end.
How DevOpsArk handles software bill of materials
Articles on this subject
Container security: the practices that actually reduce risk
Build-time hardening, runtime restriction and supply chain controls for containers, ordered by how much risk each one removes rather than by how often it is mentioned.
Vulnerability management: turning a report into a work queue
How to make a twelve-thousand-row vulnerability report actionable: deduplication, exposure-based ranking, ownership and verified closure.
More definitions
See these concepts in a running system
A 30-minute walkthrough against your own infrastructure rather than a slide about the theory.