# SBOM

> Software bill of materials — the inventory of every component and version inside a piece of software, so 'are we vulnerable to X' is a lookup, not an excavation.

When a critical vulnerability lands in a popular library, the first question is 'do we run it, and where'. Without an SBOM that answer is a panicked grep; with one it is a query. Generated automatically in CI, it turns dependency chaos into a document.

It also answers the commercial version of the question: customers and auditors increasingly ask for the component list before they buy. An SBOM says you know what you ship — the absence of one says the opposite, loudly.

## Related terms

- https://dfieldsolutions.com/en/glossary/supply-chain-attack.md
- https://dfieldsolutions.com/en/glossary/ci-cd.md
- https://dfieldsolutions.com/en/glossary/security-audit.md

---

Source: https://dfieldsolutions.com/en/glossary/sbom
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
