SBOM Best Practices for Development Teams | Sonatype Guide

SBOM Best Practices for Development Teams

Adopt sound practices and tools for creating SBOMs and making them part of development build pipelines.

Download the Sheet

Integrate SBOM Management Into Your Development Lifecycle

Automate SBOM Generation and Updates

Prioritize Vulnerability Tracking and Management at All Levels

Treat SBOMs as Sensitive Information

Regularly Review SBOMs for Licensing and Compliance Issues

Use an Exchangeable Standard Format as Part of Your SDLC

Adopt standard formats to simplify the process and minimize mistakes. These formats allow SBOMs to be automatically generated during the development process.

CYCLONEDX

CycloneDX is an open-source standard developed by the Open Web Application Security Project (OWASP) community. It was designed specifically to bolster security across software supply chains and is known for its lightweight nature. It fosters an environment where adoption and integration into build pipelines are seamless and efficient. Notably, CycloneDX is engineered for cyber risk mitigation, gaining the trust of critical sectors such as government and defense. It boasts compatibility with over 200 tools and extends its reach across more than 20 programming languages.

SPDX

SDPX is an open-source blueprint for SBOMs that simplifies the conveyance of essential details such as software names, versions, components, licenses, copyrights, and security references. It excels at reducing redundancies and streamlining distribution and compliance processes, backed by its ISO/IEC recognition as an international standard. Key attributes of SPDX include:

Understand SBOM Limitations

The objective of an SBOM is to provide a clear and comprehensive description of the contents of the software you deliver. Given the complexity of modern build processes and the relative newness of SBOM tooling, it’s important to recognize that not every SBOM will be as comprehensive as possible and that most SBOM generators focus on one type of content. A considerable number of SBOMs will be required to cover all the content of a software application. The goal of SBOMs being aggregators of SBOMs from previous build steps has yet to be achieved.