SBOMs are easy for one project, monumental at scale

Think of an SBOM as your ingredient list. A common language describing everything that goes into a piece of software, every dependency and version, in one place.

This video covers why SBOMs have gone from niche to mandatory, and why they're harder to pull off than the concept suggests:

  • SBOMs are becoming a core requirement in Europe under the Cyber Resilience Act
  • Generating an SBOM for a single project is manageable. Doing it across an organization with hundreds or thousands of developers, building some software in-house and sourcing the rest from third-party vendors, is a monumental task
  • On top of scale, there's a real decision to make about where in the pipeline you generate it – source code time, build pipeline, or deployment – and mapping out how it all comes together

The concept is simple. Operationalizing it across a large, diverse tech stack is where it gets hard.

See how Cloudsmith helps teams generate and maintain SBOMs at scale: https://cloudsmith.com

#SBOM #SupplyChainSecurity #DevSecOps #ArtifactManagement #cloudsmith