I’m not surprised that SBOM adoption is so low, almost all the efforts around SBOMs have been compliance theatre, not actually tackling the hard work of working out which software is being packaged.
There’s also zero incentives for open source to generate or use sboms, it’s just companies trying to sell products based on EU directives.
For developers package managers and lockfiles do almost everything they need.
SBOM getting no love from companiesAdoption still very low
enisa.europa.eu/publications/s…
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
www.enisa.europa.eu
Bruno Vernay
in reply to Techmeme • • •