Home / Companies / Cloudsmith / Blog / Post Details
Content Deep Dive

Making SBOMs Actionable Webinar [On-demand Session]

Blog post from Cloudsmith

Post Details
Company
Date Published
Author
Hillary Foster
Word Count
8,209
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Syft, Grype, Cosign, and Cloudsmith are tools that can improve supply chain security workflows by enhancing visibility and preventing disasters like Log4J. Software Bill of Materials (SBOMs) is a list of all components in a software product, which can help identify vulnerabilities and ensure trust in the software supply chain. Sift and Grype are tools used to generate SBOMs, while Cosign and Cloudsmith provide integration with these tools to host and analyze SBOMs. The future of SBOMs involves making them actionable, integrating tooling into CI/CD workflows, and providing interfaces for users to bring in custom information. As the community matures, we can expect to see more seamless integration of SBOMs into the software ecosystem.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Developer Experience 9 189 98 62 -18%
Real-time 2 1,339 356 133 -5%
Kubernetes 1 1,038 150 61 +1%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.