What is a software bill of materials (SBOM)?

By Sonatype on September 27, 2021 software bill of materials

6 minute read time

A deep dive into a Software Bill of Materials with top use cases, benefits, and ways to manage.
Read More...

How does securing the software supply chain fit the DoD CIO zero trust architecture?

By Sonatype on June 24, 2021 software bill of materials

8 minute read time

Curious how the DoD Zero Trust Architecture relates to secure development and protecting your software supply chain? We're breaking that down for you.
Read More...

SBOM – From the idea of transparency to the reality of code

4 minute read time

Allan Friedman from the NTIA has been working on SBOM standards in government and industry, for years. He spoke at ELEVATE 2021 about their status and future.
Read More...

Biden executive order on cybersecurity calls for enhanced software supply chain security

3 minute read time

Biden's Cybersecurity Executive Order mandates software supply chain security and secure development practices, including creating a software bill of materials.
Read More...

Using a software bill of materials (SBOM) is going mainstream

3 minute read time

Crazy: OWASP A9 is about to turn seven and the DevSecOps Community Survey shows less than half of organizations can produce a Software Bill of Materials.
Read More...

Why You Need a Software Bill of Materials More Than Ever

By Katie McCaskey on December 05, 2019 software bill of materials

5 minute read time

Enterprises need to know what open source components are in their software at all times. If you don't have a software bill of materials, you're already behind.
Read More...

US Energy and Commerce Committee: 6 Strategies for Modern Cybersecurity Risks

By Ilkka Turunen on December 18, 2018 software bill of materials

5 minute read time

On the 12th of December the Subcommittee on oversight and investigations released an additional report identifying the core strategies organisations can take.
Read More...

WSJ on Struts: Companies Still Downloading Flaw Linked to Equifax Breach

2 minute read time

The Wall Street Journal discusses open-source governance, Struts and how companies are still downloading the flaw that led to the Equifax Breach
Read More...

Eight More Struts Breaches

3 minute read time

When using vulnerable versions of the framework, organizations are breached.
Read More...