SBoM Diffing: Next Frontier for Supply Chain Security
worklifenotes.com·21h·
Discuss: Hacker News
Flag this post

SBOM Diffing Changes - Changes road sign

I’ve been thinking about continuous SBOM diffing for a while, but the subject appears to be even more important than I initially thought.

Yesterday (November 11, 2025) I attended SBOMit workshop which was a part of KubeCon NA 2025. SBOMit is an OpenSSF project which deals with SBOM correctness, validity and verification.

Specifically, the demo shown during the workshop highlighted hidden dependencies, files and network traffic that may be missed when running traditional SBOM generation tools without additional supervision – done via Witness in the demo.

I must say that at the moment the p…

Similar Posts

Loading similar posts...