Glossary

Software bill of materials

A software bill of materials is a machine-readable inventory of every component and dependency contained in a piece of software, including versions.

Short answer

What is software bill of materials?

A software bill of materials is a machine-readable inventory of every component and dependency contained in a piece of software, including versions.

Explained two ways

Plain and technical

In plain terms

An SBOM lists everything inside your application (every library, every operating system package), so when a vulnerability is announced you can immediately tell whether you are affected.

Technically

An SBOM is typically expressed in SPDX or CycloneDX format and generated at build time, capturing direct and transitive dependencies with their versions and licences. Its operational value is query speed: with an SBOM index, identifying affected services after a disclosure is a lookup rather than a rescan of the estate.

Example

What it looks like in practice

A critical vulnerability is announced in a widely used logging library. Querying the SBOM index returns the eleven affected services and which of them are internet-reachable, within seconds.
Keep going

More definitions

See these concepts in a running system

A 30-minute walkthrough against your own infrastructure rather than a slide about the theory.