SBOM Format Conversion: Tools and Techniques
Your supplier sends SPDX, your platform expects CycloneDX. Here's how to convert between SBOM formats without losing critical data.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
Your supplier sends SPDX, your platform expects CycloneDX. Here's how to convert between SBOM formats without losing critical data.
Most dependency audits get done in a panic after a CVE lands. A planned year-end audit is cheaper, more thorough, and produces a backlog you can actually work through in Q1.
A review of Tern, the open source tool that generates SBOMs by inspecting container image layers, including its strengths, limitations, and where it fits in your toolchain.
Container images are opaque by default. Here's how to crack them open with SBOMs to see exactly what's running in production.
SPDX is the ISO-standardized SBOM format. Here's how to use it effectively for security, not just license compliance.
Trivy combines SBOM generation with vulnerability scanning in a single tool. Here's how to use both capabilities effectively.
A practical, step-by-step guide to generating your first Software Bill of Materials using open-source tools and integrating it into your development workflow.
Docker Scout brings vulnerability scanning directly into the Docker CLI. Here is what it actually catches, where it falls short, and how to integrate it into your workflow.
Everything you need to know about Software Bills of Materials -- what they are, why they matter, and how to start generating them for your projects.
Weekly insights on software supply chain security, delivered to your inbox.