SBOM Guide

SBOM in practice

Create an SBOM, build it into the pipeline, share it in the supply chain and require it in procurement.

  • How to create an SBOM

    An SBOM is created by a tool that reads source code, build output or a container image. This page lists open-source tools, example commands and how to review the result.

  • Why is SBOM quality important?

    An SBOM that lacks versions, identifiers or transitive dependencies leads to vulnerability analyses that miss real problems. These are the most common gaps and how to check for them.

  • SBOM and DevOps

    An SBOM created automatically in the build pipeline is always current and costs no extra work per release. These are the steps: create, check, store and monitor.

  • SBOM in software supply chains

    Software is built from components from many suppliers, which in turn build on components from others. This page covers why the supply chain is attacked, what needs to be shared between the links and how that works in practice.

  • SBOM in public procurement

    An SBOM requirement in a procurement needs to state format, content, delivery and updates to be possible to follow up. This page covers what the requirement should contain, with example wording.