Component Hashes in SBOMs

CISA 2026 SBOM Minimum Elements mandates per-component digests or hashes as a minimum element. I believe this is the most controversial and problematic change in the requirements. That is if we want those hashes to have some meaning. Apparently, there are 2 intended meanings: Here is why verification is an issue. My favourite example is… Continue reading Component Hashes in SBOMs