REVIEW 2 cited by
A Landscape Study of Open Source and Proprietary Tools for Software Bill of Materials (SBOM)
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Modern software applications heavily rely on diverse third-party components, libraries, and frameworks sourced from various vendors and open source repositories, presenting a complex challenge for securing the software supply chain. To address this complexity, the adoption of a Software Bill of Materials (SBOM) has emerged as a promising solution, offering a centralized repository that inventories all third-party components and dependencies used in an application. Recent supply chain breaches, exemplified by the SolarWinds attack, underscore the urgent need to enhance software security and mitigate vulnerability risks, with SBOMs playing a pivotal role in this endeavor by revealing potential vulnerabilities, outdated components, and unsupported elements. This research paper conducts an extensive empirical analysis to assess the current landscape of open-source and proprietary tools related to SBOM. We investigate emerging use cases in software supply chain security and identify gaps in SBOM technologies. Our analysis encompasses 84 tools, providing a snapshot of the current market and highlighting areas for improvement.
Forward citations
Cited by 2 Pith papers
-
Policy-driven Software Bill of Materials on GitHub: An Empirical Study
Only 0.56% of popular GitHub repositories contain policy-driven SBOMs, and the dependencies they list include 2,202 unique known vulnerabilities with 22% of SBOMs lacking license information.
-
VDGraph: A Graph-Theoretic Approach to Unlock Insights from SBOM and SCA Data
VDGraph integrates SBOM and SCA data into a queryable graph and shows, on 21 Java projects, that vulnerabilities concentrate in deeply nested transitive dependencies reachable through many paths.
Discussion (0). Sign in to comment.