Component Hashes in SBOMs

CISA 2026 SBOM Minimum Elements mandates per-component digests or hashes as a minimum element. I believe this is the most controversial and problematic change in the requirements. That is if we want those hashes to have some meaning. Apparently, there are 2 intended meanings: Here is why verification is an issue. My favourite example is… Continue reading Component Hashes in SBOMs

SBOM Diffing: Next Frontier for Supply Chain Security

I’ve been thinking about continuous SBOM diffing for a while, but the subject appears to be even more important than I initially thought. Yesterday (November 11, 2025) I attended SBOMit workshop which was a part of KubeCon NA 2025. SBOMit is an OpenSSF project which deals with SBOM correctness, validity and verification. Specifically, the demo… Continue reading SBOM Diffing: Next Frontier for Supply Chain Security