sbom
3 posts · all writing
The analysis your supplier already did
Your vendor knows which CVEs in their component are actually reachable. They wrote it down. Then you retyped their conclusion into your own config, where it became a decision you are answerable for. Why consuming a VEX document beats copying it, and what the record looks like when the claim keeps its author.
The license nobody gated on: copyleft in your dependency tree
A CVE is embarrassing and fixable. A copyleft obligation you have been shipping for two years is neither, and you find out during due diligence. How to gate a build on license policy with Trivy or Mend, why permissive licenses should not be findings, and why this belongs on a different threshold from your CVEs.
The SBOM you ship is half an answer: pairing CycloneDX with VEX
An SBOM tells your customers what you are made of. Left on its own, it also hands them a list of every CVE they can match against you, and no way to tell which ones matter. The other half is VEX, and most of it is already in your descriptor.