# How Software Bill of Materials change the dependency game

DevFeed: [How Software Bill of Materials change the dependency game](<https://devfeed.tech/articles/how-software-bill-of-materials-change-the-dependency-game-47454.md>)

Original publisher: [Read original article](<https://engineering.zalando.com/posts/2023/04/how-sboms-change-the-dependency-game.html>)

Author: Bartosz Ocytko

Published: 2023-04-12T22:00:00Z

Content type: article

Language: en

Sources: [Zalando](<https://devfeed.tech/sources/zalando-engineering-blog.md>)

Topics: [Dependency management](<https://devfeed.tech/topics/dependency-management.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Microservices](<https://devfeed.tech/topics/microservices.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Security](<https://devfeed.tech/topics/security.md>), [data lake](<https://devfeed.tech/topics/data-lake.md>)

Tags: [backend](<https://devfeed.tech/tags/backend.md>), [better](<https://devfeed.tech/tags/better.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [build-system](<https://devfeed.tech/tags/build-system.md>), [data-lake](<https://devfeed.tech/tags/data-lake.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [docker](<https://devfeed.tech/tags/docker.md>), [frontend](<https://devfeed.tech/tags/frontend.md>), [golang](<https://devfeed.tech/tags/golang.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [java](<https://devfeed.tech/tags/java.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [kotlin](<https://devfeed.tech/tags/kotlin.md>), [licensing](<https://devfeed.tech/tags/licensing.md>), [log4j](<https://devfeed.tech/tags/log4j.md>), [maven](<https://devfeed.tech/tags/maven.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [python](<https://devfeed.tech/tags/python.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [scala](<https://devfeed.tech/tags/scala.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [typescript](<https://devfeed.tech/tags/typescript.md>), [zalando](<https://devfeed.tech/tags/zalando.md>)

## AI overview

This post explains how Software Bill of Materials (SBOMs) provide dependency visibility across thousands of microservices. It describes using SBOM data from deployed container images to identify affected applications, assess vulnerability and licensing impacts, and track dependency updates and patches.

## Source excerpt

In this post, we explain what questions and insights Software Bill of Materials (SBOMs) provide across thousands of microservices