Togoder security

Glossary

What is an SBOM?

Also called: software bill of materials, SPDX, CycloneDXUpdated

Definition

An SBOM (software bill of materials) is a machine-readable inventory of the components in a piece of software, including each open-source package, its version, supplier and license, usually in the SPDX or CycloneDX format.

SBOM formats

FormatMaintained byNotes
SPDXLinux FoundationISO/IEC 5962 standard; strong on licensing
CycloneDXOWASPSecurity-focused; also covers services and vulnerabilities (VEX)

US Executive Order 14028 (2021) made SBOMs a requirement for software sold to the federal government, and the EU Cyber Resilience Act pushes in the same direction.

How to generate an SBOM

npm sbom --sbom-format cyclonedx > sbom.json
syft dir:. -o spdx-json > sbom.spdx.json
cdxgen -o bom.json

Microsoft's sbom-tool and Trivy can also produce SPDX or CycloneDX output.

What an SBOM does not tell you

An SBOM lists what is there; it says nothing about whether a component is malicious. It becomes useful for security when you match it against vulnerability databases (SCA) and when you need to answer "do we ship the compromised version?" during an incident. Malicious code that has not been reported yet needs source review, which is what Togoder Security does for every package in a lockfile.

Frequently asked questions

What is the difference between an SBOM and a lockfile?

A lockfile is a package manager's install instruction for one ecosystem. An SBOM is a standard, tool-neutral inventory that can cover several ecosystems, containers and system libraries, plus metadata like suppliers and licenses.

SPDX or CycloneDX?

Both are widely supported. CycloneDX is common in security tooling; SPDX is common for license compliance. Most generators can output either.