Generating SBOMs from Container Images: A Practical Guide
Container images are opaque by default. Here's how to crack them open with SBOMs to see exactly what's running in production.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
Container images are opaque by default. Here's how to crack them open with SBOMs to see exactly what's running in production.
Standing up an SBOM program is more than picking a tool. This guide covers organizational buy-in, tooling selection, automation, and scaling from your first BOM to enterprise-wide adoption.
SPDX is the ISO-standardized SBOM format. Here's how to use it effectively for security, not just license compliance.
Trivy combines SBOM generation with vulnerability scanning in a single tool. Here's how to use both capabilities effectively.
Everything you need to know about Software Bills of Materials -- what they are, why they matter, and how to start generating them for your projects.
CycloneDX is more than a component list. This deep dive covers services, vulnerabilities, compositions, and the parts of the spec most teams overlook.
Syft is the most popular open-source SBOM generator. Here's how to use it effectively for containers, directories, archives, and CI/CD pipelines.
Weekly insights on software supply chain security, delivered to your inbox.