When a critical vulnerability lands in a popular library, the first question is 'do we run it, and where'. Without an SBOM that answer is a panicked grep; with one it is a query. Generated automatically in CI, it turns dependency chaos into a document.
It also answers the commercial version of the question: customers and auditors increasingly ask for the component list before they buy. An SBOM says you know what you ship — the absence of one says the opposite, loudly.
Related terms
Supply-chain attack
Attacking you through something you trust — a poisoned dependency, a compromised build tool — instead of attacking you directly.
CI/CD
Automatically building and testing every change, and automatically shipping the ones that pass.
Security audit
A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
