Proposal: Safety Relevance Metadata as a Missing Layer in Automotive SBOM — Bridging Static Inventory and Operational Risk #2
devashridatta-dotcom
started this conversation in
Ideas
Replies: 1 comment
|
@devashridatta-dotcom |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Submitting a proposal for discussion in an upcoming OpenChain Automotive session — feedback welcome.
Discussion Title
Proposal: Safety Relevance Metadata as a Missing Layer in Automotive SBOM — Bridging Static Inventory and Operational Risk
Background
Automotive software systems are increasingly governed by frameworks such as ISO 26262 (functional safety) and UN Regulation No. 155 (cybersecurity management systems). As Automotive SBOM approaches its Version 1.0 release, a structural gap remains: standard SBOM formats provide comprehensive component inventory, but they do not encode which components actively participate in safety-critical execution paths.
This gap has meaningful implications. A vulnerability affecting a non-safety-relevant logging library is operationally distinct from one affecting a braking control stack — yet current SBOM/VEX structures treat both identically at the metadata level. The result is triage overhead, misprioritized remediation, and compliance artifacts that do not reflect real operational risk.
Proposal Summary
I propose a focused discussion (and optionally a formal working session) on introducing Safety Relevance metadata as a standardized annotation layer for Automotive SBOM.
The Safety Relevance Index and Labeling (SRIL) framework introduces structured classification of software components based on their role in safety-critical execution:
Illustrative Automotive Component Mapping
openssl 3.xzlib 1.2.xFreeRTOS kernelTensorFlow Litelog4cxxKey Benefits
Why Now
The Automotive SBOM v1.0 timeline (target October 2026) presents an ideal window to address this gap. After v1.0 stabilization, safety relevance becomes a versioning extension rather than a design-layer consideration.
Relevant ongoing discussions:
Proposed Session Format
Option A — Live Session (15 min)
Overview + mapping + examples + discussion
Option B — Async feedback via this discussion
About the Proposer
Devashri Datta — Independent researcher in software supply chain security governance.
References
https://www.linkedin.com/in/devashri-datta-522b364b/
``
All reactions