Home / Companies / Confluent / Blog / Post Details
Content Deep Dive

Introducing Software Bill of Materials for Confluent Platform

Blog post from Confluent

Post Details
Company
Date Published
Author
Jan Werner
Word Count
1,369
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

Software supply chains are increasingly difficult to secure and manage because products contain numerous direct and transitive dependencies, making it challenging to identify affected systems when vulnerabilities emerge. Software Bills of Materials (SBOMs) address this by providing detailed, relationship-preserving inventories of components and dependencies, supporting vulnerability management, compliance, and transparency. Confluent began providing SBOMs for every major, minor, and patch Confluent Platform release starting with version 7.4, generating them during build and packaging stages with Trivy, CycloneDX CLI, and Dependency Track while excluding non-shipped test and development components. The SBOMs are published in CycloneDX and SPDX formats with cryptographic checksums in the Confluent Packages Repository for RPMs, community distributions, and container images. Users can inspect component inventories, determine whether products include vulnerable dependencies, and analyze SBOMs with software composition analysis tools or a Confluent-preconfigured local Dependency Track image, although its vulnerability analyzer is currently disabled. Confluent also plans to extend SBOM coverage to additional products and provide Vulnerability Exploitability Exchange advisories to clarify the practical impact of known vulnerabilities.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 1 3,396 269 77 +112%
Real-time 1 2,035 534 182 -15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.