What Is SBOM (Software Bill of Materials)?
A formal inventory of all software components, libraries, and dependencies in an application.
Definition
A formal inventory of all software components, libraries, and dependencies in an application.
CDEs can auto-generate SBOMs at build time to meet supply chain security requirements like US Executive Order 14028 and the EU Cyber Resilience Act.
Where This Fits
This term is covered in depth on Software Supply Chain Security for CDEs.
Securing the software supply chain with CDEs: SBOM generation, SLSA framework, Sigstore artifact signing, and policy enforcement for development.
