For a long time I was preaching the idea that an SBOM can and should essentially be split into 2 parts. The first part is static – that is the actual list of all software components with their fixed metadata (version, purl, hashes, etc). The second part is dynamic – that is things related to… Continue reading SBOM – Not So Static After All