SBOM & VEX
You will learn what a bill of materials really contains, how SPDX and CycloneDX differ, and how VEX turns an inventory into a defensible answer about whether a CVE is exploitable here.
on this pageshowhide
explore
- Producing The Inventory12 questions
- NTIA Minimum Elements4 questions
- Generation Vantage Points4 questions
- Generators In Practice4 questions
- Naming The Components8 questions
- SPDX Versus CycloneDX4 questions
- Component Identity Matching4 questions
- Exploitability & Consumption16 questions
- VEX Statuses & Justifications4 questions
- Estate Ingestion & Query4 questions
- Supplier Inventories As Evidence4 questions
- Completeness Versus Accuracy4 questions
questions
page 2 of 2How do you reach trustworthy SBOM estate coverage when operators can publish artifacts outside CI?
basics
~20 sMeasure coverage against what the runtime platform says is running, not what your pipelines produced. Then choose deliberately: make the recorded path the only route to production, or accept a measured gap with a named owner.
An internal team edits components out of the SBOM it uploads to a customer's procurement portal. How do you stop that?
basics
~20 sTreat trimming as a non-repudiation problem, not an inventory one. Remove the human hands between generation and delivery: the delivered document is the generated artefact, bound to the artefact digest, retained, and independently re-derived for a sample of releases.
With hundreds of suppliers, how do you decide which must hand over a component inventory?
basics
~20 sTier by what a supplier can reach if it goes wrong and how replaceable it is, not by contract value. Demand most from software running inside your trust boundary, and ask operators with standing production access for access evidence instead.
Should you republish a supplier's VEX not_affected claims under your own name for a composed product?
basics
~10 sNot verbatim. Authoring a statement makes you the accountable party, and a supplier's justification was evaluated against the supplier's build, not your composition. Pass through only structural claims; re-evaluate every configuration-dependent one.
A vendor ships an appliance as an RPM under its own product name with no component list — what do you do?
basics
~20 sYou cannot compute identity for someone else's build, so the levers are contractual: require a component-level SBOM and a product-keyed advisory channel as purchase terms. Until then, record one opaque component and spend on containment.
Where do you mandate SBOM generation across 400 services and artifacts you do not build yourself?
basics
~20 sDefault to build-time generation inside shared pipeline templates, since it has the highest fidelity. Fall back to artifact analysis at the registry for everything else, and require a document contractually for artifacts a supplier builds.
showing 31–36 of 36