The Minimum Elements for a Software Bill of Materials (SBOM)¶
National Telecommunications and Information Administration (NTIA). (2021). The Minimum Elements for a Software Bill of Materials (SBOM).
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Complete Enumeration
- In software, a bill of materials and transitive dependency closure enable blast-radius analysis, which requires every transitive dependency, since a sampled dependency tree is useless for "who is downstream of this vulnerable library?"
This sourceSpecifies that an SBOM should enumerate components and their transitive dependencies (the full dependency closure), enabling blast-radius/vulnerability analysis that a sampled dependency tree cannot support. (Resolves needs-source-003 with a software-supply-chain-security reference.)
- In software, a bill of materials and transitive dependency closure enable blast-radius analysis, which requires every transitive dependency, since a sampled dependency tree is useless for "who is downstream of this vulnerable library?"
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:4be966f4723a · see in the full table