# software bill of materials

Published articles for software bill of materials.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Super SBOMs: See exactly what's inside

DevFeed: [Super SBOMs: See exactly what's inside](<https://devfeed.tech/articles/super-sboms-see-exactly-what-s-inside-13245.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/super-sboms-see-exactly-whats-inside>)

Published: 2026-01-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [spdx](<https://devfeed.tech/topics/spdx.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard Containers now provide richer SBOMs with binary-level details about embedded libraries and dependencies, along with CycloneDX support in addition to SPDX. The added visibility helps teams trace vulnerabilities and assess license compliance.

### Source excerpt

Chainguard Containers ship richer SBOMs with binary-level library details plus new CycloneDX support, making CVE impact and compliance tracing fast and clear.

## Creating SBOMs with the Snyk CLI

DevFeed: [Creating SBOMs with the Snyk CLI](<https://devfeed.tech/articles/creating-sboms-with-the-snyk-cli-7873.md>)

Original publisher: [Read original article](<https://snyk.io/blog/creating-sboms-snyk-cli/>)

Author: Brian Vermeer

Published: 2025-02-05T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Software](<https://devfeed.tech/topics/software.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cli](<https://devfeed.tech/tags/cli.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [java](<https://devfeed.tech/tags/java.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains software bills of materials (SBOMs), their importance for open source security and compliance, and how the Snyk CLI can help create them. It describes SBOMs as inventories of software components, dependencies, versions, and licensing information, and explains how they help assess vulnerability exposure.

### Source excerpt

In this post, we'll delve into what SBOMs are, why they're necessary, and their role in open source security.

## Chainguard Images are the Gold Standard for PCI DSS v4.0

DevFeed: [Chainguard Images are the Gold Standard for PCI DSS v4.0](<https://devfeed.tech/articles/chainguard-images-are-the-gold-standard-for-pci-dss-v4-0-12954.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-are-the-gold-standard-for-pci-dss-v4-0>)

Published: 2025-02-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [financial](<https://devfeed.tech/tags/financial.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [pci-dss-v4-0](<https://devfeed.tech/tags/pci-dss-v4-0.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [stig](<https://devfeed.tech/tags/stig.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how Chainguard Images can support selected PCI DSS v4.0 container-security controls. It focuses on asset and vulnerability management, hardened images, FIPS cryptography, build-time SBOMs, software supply chain inventory, and continuously updated containers.

### Source excerpt

Chainguard Images are designed to make container image compliance for PCI DSS v4.0 easy for any company involved in card transactions.

## Software Bill of Materials (SBOM) for your Spin Apps

DevFeed: [Software Bill of Materials (SBOM) for your Spin Apps](<https://devfeed.tech/articles/software-bill-of-materials-sbom-for-your-spin-apps-15336.md>)

Original publisher: [Read original article](<https://www.fermyon.com/blog/sbom-for-your-spin-apps>)

Author: Thorsten Hans

Published: 2025-01-16T12:00:00Z

Content type: tutorial

Language: en

Sources: [Fermyon - Experience the next wave of cloud computing.](<https://devfeed.tech/sources/fermyon-experience-the-next-wave-of-cloud-computing.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [open-source](<https://devfeed.tech/tags/open-source.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

A tutorial on creating Software Bills of Materials for Spin apps, addressing regulatory requirements and software supply chain security with open-source tools such as Trivy.

### Source excerpt

Learn how to create SBOMs for Spin apps, meet regulatory requirements, and secure your software supply chain with open-source tools like Trivy

## Get Smart in 5 Minutes: Vulnerability remediation unveiled

DevFeed: [Get Smart in 5 Minutes: Vulnerability remediation unveiled](<https://devfeed.tech/articles/get-smart-in-5-minutes-vulnerability-remediation-unveiled-13060.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-smart-in-5-minutes-vulnerability-remediation-unveiled>)

Published: 2024-08-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [developer](<https://devfeed.tech/tags/developer.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This introductory article explains vulnerability remediation as the process of fixing flaws identified by software scanners. It describes common obstacles, including triage, uncertainty about the affected code, and unclear ownership. It presents software bills of materials (SBOMs) as a way to identify software components, while noting that outdated or inaccurate SBOMs may miss vulnerabilities or malware. The article emphasizes that software vulnerabilities can affect everyone through data breaches, service disruptions, and physical harm.

### Source excerpt

Learn the basics of vulnerability remediation from this teaser of Chainguard's Get Smart in Five Minutes series on Youtube.

## Mitigating software supply chain risks through faster vulnerability response and verified software images

DevFeed: [Mitigating software supply chain risks through faster vulnerability response and verified software images](<https://devfeed.tech/articles/if-xz-s-backdoors-are-inevitable-how-do-we-stay-secure-the-answer-is-move-faster-13100.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/if-xzs-backdoors-are-inevitable-how-do-we-stay-secure-the-answer-is-move-faster>)

Published: 2024-04-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply chain attacks](<https://devfeed.tech/topics/supply-chain-attacks.md>)

Tags: [auditability](<https://devfeed.tech/tags/auditability.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve-2024-3094](<https://devfeed.tech/tags/cve-2024-3094.md>), [golang](<https://devfeed.tech/tags/golang.md>), [liblzma](<https://devfeed.tech/tags/liblzma.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xz](<https://devfeed.tech/tags/xz.md>), [xz-backdoor](<https://devfeed.tech/tags/xz-backdoor.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

The article discusses the xz vulnerability, the risk of future software supply chain attacks, and the importance of rapid patch propagation and software inventory auditability. It presents Chainguard Images as a continuously verified and auditable approach to mitigating these risks.

### Source excerpt

Software backdoors are a threat. Learn how to mitigate supply chain security risks by responding faster to vulnerabilities like the xz flaw.

## Reproducible Builds at FOSDEM 2024

DevFeed: [Reproducible Builds at FOSDEM 2024](<https://devfeed.tech/articles/reproducible-builds-at-fosdem-2024-34158.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2024/02/08/reproducible-builds-at-fosdem-2024/>)

Published: 2024-02-08T00:00:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [FOSDEM](<https://devfeed.tech/topics/fosdem.md>), [Arch Linux](<https://devfeed.tech/topics/archlinux.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Fedora](<https://devfeed.tech/topics/fedora.md>), [coreboot](<https://devfeed.tech/topics/coreboot.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [coreboot](<https://devfeed.tech/tags/coreboot.md>), [debian](<https://devfeed.tech/tags/debian.md>), [fedora](<https://devfeed.tech/tags/fedora.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [org](<https://devfeed.tech/tags/org.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>)

### AI overview

The article reports on Reproducible Builds activities at FOSDEM 2024. It highlights Holger Levsen's talk covering the project's history, current state, and future goals, along with other talks on reproducibility, confidential computing, RISC-V bootstrapping, reproducible development environments, HPC experiments, configuration options, and software bills of materials.

### Source excerpt

Core Reproducible Builds developer Holger Levsen presented at the main track at FOSDEM on Saturday 3rd February this year in Brussels, Belgium. Titled Reproducible Builds: The First Ten Years... In this talk Holger 'h01ger' Levsen will give an overview about Reproducible Builds: How it started with a small BoF at DebConf13 (and before), then grew from being a Debian effort to something many projects work on together, until in 2021 it was mentioned in an Executive Order of the President of the United States. And of course, the talk will not end there, but rather outline where we are today and where we still need to be going, until Debian stable (and other distros!) will be 100% reproducible, verified by many. h01ger has been involved in reproducible builds since 2014 and so far has set up automated reproducibility testing for Debian, Fedora, Arch Linux, FreeBSD, NetBSD and coreboot. More information can be found on FOSDEM's own page for the talk, including a video recording and slides. Separate from Holger's talk, however, there were a number of other talks about reproducible builds at FOSDEM this year: Reproducible builds for confidential computing: Why remote attestation is worthless without it by Malte Poll and Paul Meyer. RISC-V Bootstrapping in Guix and Live-Bootstrap by Ekaitz. rix: an R package for reproducible dev environments with Nix by Bruno Rodrigues. Making reproducible and publishable large-scale HPC experiments by Philippe Swartvagher. Documenting and Fixing Non-Reproducible Builds due to Configuration Options by RANDRIANAINA Georges Aaron. ... and there was even an entire track on Software Bill of Materials.

## Software development security redefined: Sourcegraph's story

DevFeed: [Software development security redefined: Sourcegraph's story](<https://devfeed.tech/articles/software-development-security-redefined-sourcegraph-s-story-13236.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/software-development-security-redefined-sourcegraphs-story>)

Published: 2023-12-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [customer-story](<https://devfeed.tech/tags/customer-story.md>), [cve](<https://devfeed.tech/tags/cve.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sourcegraph](<https://devfeed.tech/tags/sourcegraph.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This customer story describes how Sourcegraph used Chainguard Images, built on Wolfi OS, together with OpenVEX and SBOMs to simplify vulnerability management and strengthen software supply chain security. The article states that Sourcegraph achieved zero known vulnerabilities in a short timespan.

### Source excerpt

Sourcegraph's story: leveraging Chainguard's technology for streamlined software development and heightened security.

## Top 5 takeaways from KubeCon NA 2023: SSCS, Wolfi and more

DevFeed: [Top 5 takeaways from KubeCon NA 2023: SSCS, Wolfi and more](<https://devfeed.tech/articles/top-5-takeaways-from-kubecon-na-2023-sscs-wolfi-and-more-13296.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/top-5-takeaways-from-kubecon-na-2023-sscs-wolfi-and-more>)

Published: 2023-11-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubecon-na](<https://devfeed.tech/tags/kubecon-na.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sscs](<https://devfeed.tech/tags/sscs.md>), [wofli](<https://devfeed.tech/tags/wofli.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard reviews five takeaways from KubeCon North America 2023, focusing on the event's growth, the rising awareness of software supply chain security, and the shift toward implementing security tools and processes within software development. The article also highlights SBOMs, digital signatures, attestations, Wolfi, and related cloud-native topics.

### Source excerpt

Chainguard's breakdown of KubeCon NA 2023: Top five highlights in software supply chain security, Wolfi, and more.

## Secure your software supply chain with the new Snyk Vulnerability Intelligence for SBOM ServiceNow integration

DevFeed: [Secure your software supply chain with the new Snyk Vulnerability Intelligence for SBOM ServiceNow integration](<https://devfeed.tech/articles/secure-your-software-supply-chain-with-the-new-snyk-vulnerability-intelligence-for-sbom-servicenow-integration-8180.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-vulnerability-intelligence-sbom-servicenow/>)

Author: Sarah Conway

Published: 2023-11-07T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [visibility](<https://devfeed.tech/tags/visibility.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article introduces Snyk Vulnerability Intelligence for SBOM, an integration that brings Snyk vulnerability data into SBOMs stored in ServiceNow Vulnerability Response. It uses package URLs to identify vulnerable components, provides contextual severity and remediation information, and supports dashboards and workflows for tracking and fixing software supply chain risk.

### Source excerpt

The new Snyk Vulnerability Intelligence for SBOM integration brings visibility to your SBOMs in ServiceNow Vulnerability Response for a more accurate understanding of risk within the enterprise supply chain.

## Software Bill of Materials

DevFeed: [Software Bill of Materials](<https://devfeed.tech/articles/software-bill-of-materials-13961.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/software-bill-of-materials/>)

Author: John Lee

Published: 2023-11-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [iot](<https://devfeed.tech/tags/iot.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article introduces software bills of materials (SBOMs), explains their structure and formats such as SPDX and CycloneDX, and presents Espressif's ESP-IDF-SBOM tool. The tool generates SPDX SBOMs for ESP-IDF-based applications and checks them against the National Vulnerability Database for known vulnerabilities.

### Source excerpt

Overview# The "software bill of materials" (SBOM) has emerged as a key building block in software security and software supply chain risk management. An SBOM is a comprehensive list of all the software components, dependencies, and metadata associated with an application. Espressif believes that this information is a key step towards ensuring the security of the connected devices. And as such, we have now enabled easy to use tools and solutions to track and analyze this information.

## Celebrating innovation in open source software and container image security with Chainguard Images

DevFeed: [Celebrating innovation in open source software and container image security with Chainguard Images](<https://devfeed.tech/articles/celebrating-innovation-in-open-source-software-and-container-image-security-with-chainguard-images-12920.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-innovation-in-open-source-software-and-container-image-security-with-chainguard-images>)

Published: 2023-11-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard describes the growth of Chainguard Images as a secure container image offering for open source software development and software supply chain security. The article highlights more than one million image builds, over 90 million pulls, a large inventory of tools and applications, reduced CVEs, passwordless token-based authentication, SBOMs, and Sigstore-verified software signatures.

### Source excerpt

Explore the fusion of open source innovation and container security with Chainguard Images.

## Grype Adds OpenVEX Support for Vulnerability Analysis

DevFeed: [Grype Adds OpenVEX Support for Vulnerability Analysis](<https://devfeed.tech/articles/vexed-then-grype-about-it-chainguard-and-anchore-announce-grype-supports-openvex-13311.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vexed-then-grype-about-it-chainguard-and-anchore-announce-grype-supports-openvex>)

Published: 2023-10-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [openvex](<https://devfeed.tech/topics/openvex.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-and-infrastructure-security-agency](<https://devfeed.tech/tags/cybersecurity-and-infrastructure-security-agency.md>), [grype](<https://devfeed.tech/tags/grype.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

Grype, Anchore's open-source vulnerability scanner, now supports OpenVEX, a machine-readable standard for vulnerability analysis. The article explains how this can provide context for vulnerabilities and help reduce false positives and vulnerability-management effort.

### Source excerpt

Open source vulnerability scanner Grype has added support for OpenVEX, making software supply chain security easier. Learn how to implement it today.

## Working with government and industry to put open source security tooling into practice

DevFeed: [Working with government and industry to put open source security tooling into practice](<https://devfeed.tech/articles/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice-13342.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice>)

Published: 2023-09-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>)

Tags: [bombshell](<https://devfeed.tech/tags/bombshell.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [protobom](<https://devfeed.tech/tags/protobom.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard describes two open-source SBOM tools developed with the U.S. Department of Homeland Security and other startups: protobom, which translates SBOM data between formats, and bomshell, which combines and composes SBOMs. The initiative aims to improve software supply chain security and visibility.

### Source excerpt

Pioneering SBOM tools with government and industry allies, Chainguard advances open source security measures.

## How Snyk can help secure supply chains per "A Guide to Implementing the Software Bill of Materials (SBOM) for Software Management"' by Japan's METI

DevFeed: [How Snyk can help secure supply chains per "A Guide to Implementing the Software Bill of Materials (SBOM) for Software Management"' by Japan's METI](<https://devfeed.tech/articles/how-snyk-can-help-secure-supply-chains-per-a-guide-to-implementing-the-software-bill-of-materials-sbom-for-software-management-by-japan-s-meti-7989.md>)

Original publisher: [Read original article](<https://snyk.io/blog/japan-meti-guide-to-sbom-for-software-management/>)

Author: Hiroko Nakano

Published: 2023-08-01T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [asia-pacific-japan](<https://devfeed.tech/tags/asia-pacific-japan.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devops](<https://devfeed.tech/tags/devops.md>), [japan](<https://devfeed.tech/tags/japan.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains Japan's METI guidance for implementing Software Bill of Materials (SBOM) practices and describes how Snyk can help organizations create and scan SBOMs for vulnerabilities. It outlines the guide's implementation phases and discusses software supply-chain security, vulnerability management, and development productivity.

### Source excerpt

Snyk provides tools to create and scan SBOMs for vulnerabilities, helping organizations meet the requirements laid out by the METI Guide. This blog explores how Snyk can help to comply with the METI's guidance.

## Can Protobom end the SBOM format wars?

DevFeed: [Can Protobom end the SBOM format wars?](<https://devfeed.tech/articles/can-protobom-end-the-sbom-format-wars-12916.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/can-protobom-end-the-sbom-format-wars>)

Published: 2023-07-31T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Library](<https://devfeed.tech/topics/library.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [cisa](<https://devfeed.tech/tags/cisa.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [library](<https://devfeed.tech/tags/library.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [protobom](<https://devfeed.tech/tags/protobom.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>)

### AI overview

The article presents Protobom as an open source library designed to reduce the importance of choosing among SBOM formats. It provides a format-neutral representation of SBOM package and file data and translates that data between popular formats, allowing teams to focus more on software supply chain security.

### Source excerpt

Probe the SBOM format wars: Can ProtoBOM herald a new era of consensus? Chainguard weighs in.

## Celebrating 5 years of NTIA's SBOM work

DevFeed: [Celebrating 5 years of NTIA's SBOM work](<https://devfeed.tech/articles/celebrating-5-years-of-ntia-s-sbom-work-12919.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-5-years-of-ntias-sbom-work>)

Published: 2023-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [distroless](<https://devfeed.tech/topics/distroless.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sofware-supply-chain](<https://devfeed.tech/tags/sofware-supply-chain.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article commemorates five years of the NTIA's Software Bill of Materials work and reviews the development of SBOMs as a foundation of software supply chain security. It describes the NTIA's initiative, its multi-stakeholder guidelines, and CISA's continuing role in advancing software transparency.

### Source excerpt

Celebrate 5 transformative years of SBOM work with Chainguard, reflecting on the journey of software bill of materials.

## How to explain the CISA software attestation requirements to your board

DevFeed: [How to explain the CISA software attestation requirements to your board](<https://devfeed.tech/articles/how-to-explain-the-cisa-software-attestation-requirements-to-your-board-13094.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-explain-the-cisa-software-attestation-requirements-to-your-board>)

Published: 2023-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [government](<https://devfeed.tech/tags/government.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [policy](<https://devfeed.tech/tags/policy.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [signing-artifacts](<https://devfeed.tech/tags/signing-artifacts.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This article explains how software companies can brief their boards on CISA software attestation requirements and the broader federal software supply chain security policy landscape. It discusses Executive Order 14028, SBOMs, secure software development, CISA's Secure Software Development Attestation Form, and the requirements in OMB Memorandum M-22-18, including alignment with NIST guidance.

### Source excerpt

CISA's draft self-attestation form clarifies the minimum requirements that software developers must meet to comply with OMB Memorandum M-22-18.

## OSS Security: Chainguard Spring 2023 update

DevFeed: [OSS Security: Chainguard Spring 2023 update](<https://devfeed.tech/articles/oss-security-chainguard-spring-2023-update-13199.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/oss-security-chainguard-spring-2023-update>)

Published: 2023-03-22T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-security-con](<https://devfeed.tech/tags/cloud-native-security-con.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [foss](<https://devfeed.tech/tags/foss.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubecon-eu](<https://devfeed.tech/tags/kubecon-eu.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [oss](<https://devfeed.tech/tags/oss.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard's Spring 2023 update describes its involvement in open-source software security during the first part of 2023. It covers community leadership, conference talks and workshops, software freedom advocacy, and efforts to make software bills of materials useful and widely adopted for supply-chain security.

### Source excerpt

Chainguard believes open source is important and we mean it. Check out how we've been involved in OSS Security in the first part of 2023.

## Chainguard's perspective on the National Cybersecurity Strategy and secure software development

DevFeed: [Chainguard's perspective on the National Cybersecurity Strategy and secure software development](<https://devfeed.tech/articles/charting-a-secure-by-default-future-13002.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/charting-a-secure-by-default-future>)

Published: 2023-03-02T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [software-development](<https://devfeed.tech/topics/software-development.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard discusses the National Cybersecurity Strategy's implications for software liability and secure software development, highlighting SBOM tooling, NIST frameworks, memory-safe languages, and open source software security.

### Source excerpt

Chainguard's vision for a 'Secure by Default' future: Pioneering strategies to integrate security into the tech fabric.

## A purl of wisdom on SBOMs and vulnerabilities

DevFeed: [A purl of wisdom on SBOMs and vulnerabilities](<https://devfeed.tech/articles/a-purl-of-wisdom-on-sboms-and-vulnerabilities-12860.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-purl-of-wisdom-on-sboms-and-vulnerabilities>)

Published: 2023-02-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [component](<https://devfeed.tech/tags/component.md>), [components](<https://devfeed.tech/tags/components.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [false-positive](<https://devfeed.tech/tags/false-positive.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [package-url](<https://devfeed.tech/tags/package-url.md>), [purl](<https://devfeed.tech/tags/purl.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article argues that Software Bill of Materials (SBOMs) would be more useful if the National Vulnerability Database (NVD) widely adopted the package URL (purl) naming scheme. Analysis of real scanner false positives suggests that purl information could reduce the false positive rate by more than 50%.

### Source excerpt

SBOMs could be a lot more useful if the NVD implemented widespread usage of the purl naming scheme, which could reduce the false positive rate by over 50%.