Software Bills of Materials: Motivation, Formats, Tools, and Challenges
Jan Hensel
2024-07-01
Abstract
An increasing awareness of threats to the so-called “supply chain” of software has spurred rapid developments in the area of software bills of materials (SBOMs), including regulatory efforts to mandate them. This paper not only explains what SBOMs are, both abstractly and in the context of their role in increasing the security of the software supply chain, but also provides a brief survey of concrete SBOM formats, discusses the processes involving SBOMs, and explores some of the tools that facilitate SBOM use today.