1. 主题
  2. 安全防护
  3. What is an SBOM?

What is an SBOM?

CopiedFailed复制 URL

A software bill of materials (SBOM) is a list of components that make up your software applications. It includes all the components, libraries, and modules used within a software product, presented in a format that other software can read. Think of this as a list of ingredients that make up your software recipe. 

Explore Lightwell

Most modern software is built by assembling multiple pre-made, third-party components (like code libraries). When you weave a large number of components together, things can get complicated. 

Creating and maintaining an SBOM helps keep track of the versions, licenses, dependencies, and changes made to those components over time. An SBOM is a living document that acts as a source of truth, helping to identify and avoid security risks and satisfy compliance demands. 

By providing transparency into a product’s digital makeup, an SBOM is useful to people across every stage of the software lifecycle. This includes people who:

  • Develop or manufacture software: Builders can make sure components are up to date and fit their needs.
  • Select or purchase software: Buyers can evaluate risk before buying by analyzing the internal makeup of the software.
  • Operate software: System administrators and IT teams can check their software against common vulnerabilities and exposures (CVE) lists.
  • Use software: End users and consumers indirectly benefit from higher baseline security measures.

扩展阅读

什么是安全防护自动化?

安全防护自动化是指依托技术手段,在减少人工协助的情况下执行任务,从而实现安全防护流程、应用和基础架构的深度集成。

什么是 DevSecOps?

如果您想充分发挥 DevOps 的敏捷性和响应能力,则必须在应用的整个生命周期内兼顾 IT 安全性。

左移与右移:有何区别

左移和右移是指在软件开发生命周期的每个阶段都实施持续测试。

安全防护 相关资源

相关文章