Genuine question that I am struggling to get a good answer on - we have a lot SBOM tooling, and the concept in and of itself is good - but what commercial orgs (not US federal) are actually looking for SBOMs as part of their procurement requirements right now?
@fintanr 3) More nuanced but what I call "OSS sanitization" or removing non customer facing packages from your 1st party SBOMs.
I'm thinking packages with test scope for example. You would
* Generate SBOM
* Sanitize test scope dependencies
* Ingest "Customer facing" SBOM
@fintanr IMO very few non US federal orgs require SBOMs for procurement. I do however find there are significantly better SBOM use-cases
1) Managing 3rd party supply chain risk by ingesting SBOMS
2)Enriching 1st party SBOMs with vuln & exploitability data