Vulnerabilities and scanning

SBOM (Software Bill of Materials)

Software Bill of Materials is a formal inventory of the components, libraries, and dependencies that make up a software product. Executive Order 14028 (2021) directed NIST and OMB to issue guidance under which US federal agencies should require an SBOM when applicable to a procurement, and enterprise buyers increasingly ask for them too. Common formats include SPDX and CycloneDX. An SBOM lets an organization check quickly whether a newly disclosed vulnerability affects software it runs.