Introducing Software Bill of Materials for Confluent Platform
Blog post from Confluent
Software supply chains are increasingly difficult to secure and manage because products contain numerous direct and transitive dependencies, making it challenging to identify affected systems when vulnerabilities emerge. Software Bills of Materials (SBOMs) address this by providing detailed, relationship-preserving inventories of components and dependencies, supporting vulnerability management, compliance, and transparency. Confluent began providing SBOMs for every major, minor, and patch Confluent Platform release starting with version 7.4, generating them during build and packaging stages with Trivy, CycloneDX CLI, and Dependency Track while excluding non-shipped test and development components. The SBOMs are published in CycloneDX and SPDX formats with cryptographic checksums in the Confluent Packages Repository for RPMs, community distributions, and container images. Users can inspect component inventories, determine whether products include vulnerable dependencies, and analyze SBOMs with software composition analysis tools or a Confluent-preconfigured local Dependency Track image, although its vulnerability analyzer is currently disabled. Confluent also plans to extend SBOM coverage to additional products and provide Vulnerability Exploitability Exchange advisories to clarify the practical impact of known vulnerabilities.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 1 | 3,396 | 269 | 77 | +112% |
| Real-time | 1 | 2,035 | 534 | 182 | -15% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.