skip to content

SBOM & VEX

You will learn what a bill of materials really contains, how SPDX and CycloneDX differ, and how VEX turns an inventory into a defensible answer about whether a CVE is exploitable here.

on this pageshow

explore

questions

page 2 of 2

How do you reach trustworthy SBOM estate coverage when operators can publish artifacts outside CI?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Measure coverage against what the runtime platform says is running, not what your pipelines produced. Then choose deliberately: make the recorded path the only route to production, or accept a measured gap with a named owner.

open as a page

An internal team edits components out of the SBOM it uploads to a customer's procurement portal. How do you stop that?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

Treat trimming as a non-repudiation problem, not an inventory one. Remove the human hands between generation and delivery: the delivered document is the generated artefact, bound to the artefact digest, retained, and independently re-derived for a sample of releases.

open as a page

With hundreds of suppliers, how do you decide which must hand over a component inventory?

level: principalimportance: nice to knowfreq 29%

basics

~20 s

Tier by what a supplier can reach if it goes wrong and how replaceable it is, not by contract value. Demand most from software running inside your trust boundary, and ask operators with standing production access for access evidence instead.

open as a page

Should you republish a supplier's VEX not_affected claims under your own name for a composed product?

level: principalimportance: nice to knowfreq 27%

basics

~10 s

Not verbatim. Authoring a statement makes you the accountable party, and a supplier's justification was evaluated against the supplier's build, not your composition. Pass through only structural claims; re-evaluate every configuration-dependent one.

open as a page

A vendor ships an appliance as an RPM under its own product name with no component list — what do you do?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

You cannot compute identity for someone else's build, so the levers are contractual: require a component-level SBOM and a product-keyed advisory channel as purchase terms. Until then, record one opaque component and spend on containment.

open as a page

Where do you mandate SBOM generation across 400 services and artifacts you do not build yourself?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Default to build-time generation inside shared pipeline templates, since it has the highest fidelity. Fall back to artifact analysis at the registry for everything else, and require a document contractually for artifacts a supplier builds.

open as a page

showing 31–36 of 36