A Software Bill of Materials (SBOM) is a machine-readable inventory of the components in a piece of software: direct and transitive dependencies, versions, licenses, and origins. Standard formats include SPDX and CycloneDX. Regulators and large customers increasingly require SBOMs from vendors, driven by supply-chain incidents.
What an SBOM enables
- Zero-day response: when the next major CVE drops, 'do we ship this component?' becomes a query, not a week of archaeology.
- License compliance: obligations tracked per component.
- Customer trust: evidence of what is actually inside the product.
Ceremonial vs operational SBOMs
An SBOM generated once for a compliance checkbox is stale on arrival. Useful SBOMs are produced by the build pipeline on every release — which makes SBOM generation another security step whose coverage across pipelines must be enforced, like any scanner.

