Hacker News new | ask | show | jobs
by l8again 1916 days ago
Also, I wonder how can we realistically implement this for SaaS?
1 comments

Implement yes, but will it make a relevant difference? IMHO Unlikely.

A BOM no one (of relevance) ever reads is as good as no BOM.

The main positive effects a BOM can have (outside of SaaS) is to more strongly discourage to use (continue to use) of known to be problematic libraries or services.