|
|
|
|
|
by pipingdog
928 days ago
|
|
The lack of consensus is on what an SBOM is for. Even the NIST recommendation which came out of Executive Order 14028 had little guidance on how to apply SBOM . At any sort of scale, it isn't clear how an SBOM shipped with each package can be consumed to any great effect. A central database of all dependencies, on which queries and analysis can be performed, however, can be very useful, and in a large software shop, I've seen it used to rapidly get a very real sense of the company's exposure to events like the Log4j debacle. |
|