Software Bill of Materials Best Practices

Software Bill of Materials Best Practices

A software bill of materials (SBOM) is a list of all packages and libraries included in your application. It’s the digital equivalent of a manufacturing bill of materials. Just as a bill of materials includes all sub-assemblies, the SBOM also includes transitive dependencies or your components’ dependencies. And like a traditional BOM, the SBOM makes it easy to see if any risky packages are included in an application.

Generate and store an SBOM for every application

Generate an SBOM for every application during the build process

Store the SBOMs in your Sonatype SBOM Manager

Beware of the risks in sharing your SBOMs with the general public

Include the SBOM in your Lifecycle scans

Include scan results as a link in your SBOM or with your SBOM

Vulnerability data stored in an SBOM should not be used for long-term risk assessment