Are SBOMs Any Good? Preliminary Measurement of the Quality of Open Source Project SBOMs
Are SBOMs Any Good? Preliminary Measurement of the Quality of Open Source Project SBOMs
@ktrychon @simon Agreed, the value in using SBOMs for open source projects is in improving the certainty of the projects' security, since it means feeding better data to vulnerability detection tools.
To answer the question myself, as a hobbyist dev (working outside of a company), when I try to improve the security of my projects, it tends to be for moral reasons — I don't want to enable malicious people doing bad things when my code gets used by others