Web Access to SBOM Data
Proposal to Standardize SBOM access
Licensed under CC-BY-SA-3.0
Context and Background
Common Vocabulary
Network Access and Protocols
Agenda
Licensed under CC-BY-SA-3.0
Current State of SBOM Standardization
- however -
Licensed under CC-BY-SA-3.0
Open Easy Granular Access to SBOM Data
A Possible Future for SBOM’s
?
Producers
Consumers
Today
Producers
Future
SBOM “Elements”
Consumers
SBOM “Documents”
- Independent “documents”
- Overlapping data
- No standard discovery
- Granular “Elements”
- Reference rather than copy
- Discovery protocol
Licensed under CC-BY-SA-3.0
Problems Addressed in the Future Scenario
A Possible Future for SBOMs
Licensed under CC-BY-SA-3.0
Protocols
SBOM Discovery
Licensed under CC-BY-SA-3.0
RFC 9472
Protocols for SBOM Discovery
- However -
Licensed under CC-BY-SA-3.0
Question and Discussion
Licensed under CC-BY-SA-3.0
Common Vocabulary
Licensed under CC-BY-SA-3.0
SPDX
Current SBOM RDF Vocabulary Specs
Licensed under CC-BY-SA-3.0
Questions and Discussion
Licensed under CC-BY-SA-3.0