Why New Generation of SBOM Tools Matters

As a preface for what I mean by old generation tooling, here is a screenshot from Semgrep documentation: Essentially, this asks developers to centre their SBOM generation efforts around the main branch of a repository. To expand on this, legacy generation of tooling simply slaps an SBOM to a security scan, resulting in a single… Continue reading Why New Generation of SBOM Tools Matters

Practical Guide to NTIA Compliant SBOM

In this post I will describe a specific example of how we can generate an SBOM compliant to NTIA minimum specification. I will go over existing tooling, real-world issues and how to work around them. I Problem Statement The document by NTIA outlining minimum SBOM elements was published in 2021. Still, it is a challenge… Continue reading Practical Guide to NTIA Compliant SBOM

SBOMs to xBOMs to Transparency

Here is a recording of my talk at OWASP Ottawa: Slides available here: https://www.slideshare.net/slideshow/from-sboms-to-xboms-to-transparency-pavel-shukhman-at-owasp-ottawa-on-2025-03-19/277683431