1 of 38

The Current State of SBOMs for End Users

Eddie Zaneski

2 of 38

Hi, I'm Eddie

  • Staff Software Engineer @ Defense Unicorns
  • Denver, CO
  • Maintainer for Kubernetes, protobom, bomctl

3 of 38

Disclaimer

4 of 38

Disclaimer

  • I am not an SBOM expert
    • Just a dude trying to get things done
  • These are hard problems to solve
  • There will be opinions and 🔥 hot takes

5 of 38

What Is An SBOM?

6 of 38

SBOMs Are…

"A list of ingredients that make up software components"

https://www.cisa.gov/sbom

7 of 38

The SBOM Lifecycle: A Journey to Maturity

8 of 38

SBOM Type Definition and Composition

9 of 38

SBOM Type Definition and Composition

10 of 38

Why Should You Care About SBOMs?

11 of 38

Because…

  • Regulations
    • Executive Order 14028
    • FedRAMP
    • EU Cyber Resilience Act
  • Security
  • They let you do cool stuff

12 of 38

Where SBOM Things Started For Me

13 of 38

Where This Started

  • 2022 - working at Chainguard
  • I have a container image with a fancy SBOM
  • I build my app, produce an SBOM
  • I layer my app on that base image
  • How do I represent what I just made as an SBOM?

14 of 38

15 of 38

me: how do i do the thing?

puerco: the community is still figuring that out

puerco: you can combine them or produce a new one

me: which should i do and how

puerco: yes

me: …

16 of 38

Where Things Are Now

17 of 38

18 of 38

Where Things Are Now

  • April 2024
  • Produce a vulnerability report for a Zarf package
  • Zarf package has 10 bundled containers so we have 10 SBOMs
  • Vuln scanning tools don't know what a Zarf package is
  • Scan 10 SBOMs and aggregate the results or combine SBOMs

19 of 38

20 of 38

21 of 38

22 of 38

23 of 38

24 of 38

25 of 38

26 of 38

What's The Current State?

27 of 38

FORMATS

  • ~3 of them
    • CycloneDX
    • SPDX
    • SWID Tagging
    • Syft
  • Focus seems to be on spec completeness
    • Stuck in academia and "might need one day" features
    • Not on
      • End users
      • Practical use cases
      • Interoperability

28 of 38

Regulations

  • Checkboxes
    • Can pretty much submit an empty sbom.json file or a hand crafted sbom.docx
  • FedRAMP has some new changes coming

29 of 38

Tooling

  • Mostly find your own
    • There are lists out there…
  • Mostly CDX results from Google
    • Maven
    • Ruby
    • Python
    • Go
  • Syft
  • protobom & bomctl

30 of 38

Build Time vs Runtime

"You can generate a Bill of Materials using the source code during build time, during runtime, or while doing forensics on the software. Of all these, experts recommend generating an SBOM during the build time. That’s because build-time SBOM generators are more accurate and generate a more complete list of dependencies…"

31 of 38

What Do I Do With This?

  • Stick it in your SBOM folder?
  • Mostly proprietary solutions out there. "Book a demo"
  • GUAC
  • bomctl & protobom/storage

32 of 38

Best Practices

  • 🤷

33 of 38

34 of 38

Where Do I Want Things To Go?

35 of 38

Guidance

  • What are the best practices?
    • How do we tie together different SBOMs and layers?
  • Reference implementations
  • Work backwards from how we want to use these things

36 of 38

My SBOM Future

  • A format - CISA PLZ
  • Ubiquitous & Boring
    • Graph of data
    • It's all built-in and automatic
    • This includes my build tools
  • A focus on practical usage
  • Index them on a timeline

37 of 38

Where To Get Involved

  • OpenSSF Working Groups
    • SBOM Tooling WG
    • Security Tooling WG
    • Supply Chain Integrity WG
    • SBOM Everywhere SIG
  • protobom
    • Every other Wednesday @ 9am PT
  • Spec meetings

38 of 38

Thanks!

Questions?

@eddiezane.bsky.social