A Good SBOM is Hard to Find

Justin Hutchings of GitHub spoke with us about SBOMs and how developers can use the the software bill of materials to determine its security. The concept of a software bill of materials (SBOM) aims to provide consumers with information about the components inside a software, enabling better assessment of potential security issues. Justin Hutchings, Senior Director of Product Management at GitHub, emphasizes the importance of SBOMs and their potential to facilitate patching without relying solely on the vendor. He spoke with Alex Williams in this episode of The New Stack Makers. Creating a comprehensive SBOM poses challenges. Each software package is unique, such as an Android application that combines the developer's code with numerous open-source dependencies obtained through Maven packages. The SBOM should ideally serve as a machine-readable inventory of all these dependencies, enabling developers to evaluate their security. Hutchings notes that many SBOMs fall short in being fully machine-readable, and the vulnerability landscape is even more problematic. To achieve the standards Hutchings envisions, several actions are necessary. For instance, certain programming languages make it difficult to inspect build contents, while the lack of a centralized distribution point for dependencies in languages like C and C++ complicates the enumeration and standardization of machine-readable names and versions. Addressing these issues across the entire software supply chain is imperative. SBOMs hold potential for enhancing software security, but the current state of implementation and machine-readability needs improvement, particularly concerning diverse programming languages and dependency management. Learn more at thenewstack.io Creating a 'Minimum Elements' SBOM Document in 5 Minutes https://thenewstack.io/creating-a-min... Enhance Your SBOM Success with SLSA https://thenewstack.io/enhance-your-s... How to Create a Software Bill of Materials https://thenewstack.io/how-to-create-...

SLSA, SigStore, SBOM & Software Supply Chain Security. What does it all mean? - Abdel Sghiouar
▶︎

SLSA, SigStore, SBOM & Software Supply Chain Security. What does it all mean? - Abdel Sghiouar

An SBOM Primer: From Licenses to Security, Know What’s in Your Code... - Jeff Shapiro & Gary O'Neall
▶︎

An SBOM Primer: From Licenses to Security, Know What’s in Your Code... - Jeff Shapiro & Gary O'Neall

Big Techday 26: MCP and the emerging agent protocol stack - Mathias Burger & Áron Erdelyi, TNG
▶︎

Big Techday 26: MCP and the emerging agent protocol stack - Mathias Burger & Áron Erdelyi, TNG

Turing Award Winner: Disagreeing with Google, Postgres, Future Problems | Mike Stonebraker
▶︎

Turing Award Winner: Disagreeing with Google, Postgres, Future Problems | Mike Stonebraker

Episode 1 - Introduction to CycloneDX SBOM Standard
▶︎

Episode 1 - Introduction to CycloneDX SBOM Standard

Let's Assume SBOM's Exist ... Now What?
▶︎

Let's Assume SBOM's Exist ... Now What?

CSAF, Not SBOM, Is The Solution
▶︎

CSAF, Not SBOM, Is The Solution

Find Vulnerabilities In Your Code With Snyk
▶︎

Find Vulnerabilities In Your Code With Snyk

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains
▶︎

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

Something is jamming GPS over Europe. Here's what we found
▶︎

Something is jamming GPS over Europe. Here's what we found

Frequency Of God 963 Hz ✨ Attract Miracles, Divine Blessings & Deep Inner Peace In Your Life
▶︎

Frequency Of God 963 Hz ✨ Attract Miracles, Divine Blessings & Deep Inner Peace In Your Life

40K LEGENDS - TRAZYN THE INFINITE | Warhammer 40,000 Lore/History
▶︎

40K LEGENDS - TRAZYN THE INFINITE | Warhammer 40,000 Lore/History

Practical Advice for Successful SBOM Management
▶︎

Practical Advice for Successful SBOM Management

How Microsoft is governing thousands of Kubernetes clusters without manual intervention
▶︎

How Microsoft is governing thousands of Kubernetes clusters without manual intervention

Master SBOM Creation & Image Scanning for CKS Certification | Trivy & BOM CLI Explained
▶︎

Master SBOM Creation & Image Scanning for CKS Certification | Trivy & BOM CLI Explained

Skill Issue: Andrej Karpathy on Code Agents, AutoResearch, and the Loopy Era of AI
▶︎

Skill Issue: Andrej Karpathy on Code Agents, AutoResearch, and the Loopy Era of AI

Why long-running AI agents break on HTTP and how Ably is fixing it
▶︎

Why long-running AI agents break on HTTP and how Ably is fixing it

The Roots of SBOM E02
▶︎

The Roots of SBOM E02

Reinventing Entropy | Compression is Intelligence Part 1
▶︎

Reinventing Entropy | Compression is Intelligence Part 1

Scott and Mark learn...how agents reshape software engineering | BRK247
▶︎

Scott and Mark learn...how agents reshape software engineering | BRK247