Definition
An SBOM (software bill of materials) is a machine-readable inventory of the components in a piece of software, including each open-source package, its version, supplier and license, usually in the SPDX or CycloneDX format.
SBOM formats
| Format | Maintained by | Notes |
|---|---|---|
| SPDX | Linux Foundation | ISO/IEC 5962 standard; strong on licensing |
| CycloneDX | OWASP | Security-focused; also covers services and vulnerabilities (VEX) |
US Executive Order 14028 (2021) made SBOMs a requirement for software sold to the federal government, and the EU Cyber Resilience Act pushes in the same direction.
How to generate an SBOM
npm sbom --sbom-format cyclonedx > sbom.json syft dir:. -o spdx-json > sbom.spdx.json cdxgen -o bom.json
Microsoft's sbom-tool and Trivy can also produce SPDX or CycloneDX output.
What an SBOM does not tell you
An SBOM lists what is there; it says nothing about whether a component is malicious. It becomes useful for security when you match it against vulnerability databases (SCA) and when you need to answer "do we ship the compromised version?" during an incident. Malicious code that has not been reported yet needs source review, which is what Togoder Security does for every package in a lockfile.
Frequently asked questions
What is the difference between an SBOM and a lockfile?
A lockfile is a package manager's install instruction for one ecosystem. An SBOM is a standard, tool-neutral inventory that can cover several ecosystems, containers and system libraries, plus metadata like suppliers and licenses.
SPDX or CycloneDX?
Both are widely supported. CycloneDX is common in security tooling; SPDX is common for license compliance. Most generators can output either.