Skip to content

SBOM-Community/documents

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

12 Commits
 
 
 
 
 
 

Repository files navigation

CISA SBOM Community Document Repository

This repository hosts copies of various documents drafted collaboratively by the CISA SBOM Community and related efforts. This repository is intentionally incomplete until some organizational decision are made.

The maintainers acknowledge and thank CISA, NTIA, and the many volunteer contributors to this body of work on SBOM and related topics. Document summaries are largely adapted from CISA and NTIA sources.

CISA SBOM Community

These documents were developed collaboratively by the CISA SBOM Community and are hosted in the CISA SBOM Resources Library.

Framing Software Component Transparency: Establishing a Common Software Bill of Materials (SBOM)

Third Edition

September 2024 [original] [local]

Further defines and clarifies SBOM Attributes from the Second Edition, offering descriptions of the minimum expected, recommended practices, and aspirational goal for each Attribute.

Second Edition

October 2021 [original] [local]

A detailed foundation of SBOM that defines SBOM concepts and related terms, offers an updated baseline of how software components are to be represented, and discusses the processes around SBOM creation.

First Edition

2019 [original] [local]

Reviewing Vulnerability Exploitability eXchange (VEX) Practices

March 2025 [paper] [data]

To better understand how VEX is being used or considered for use today, the VEX Working Group solicited and reviewed current VEX practices.

NTIA Software Component Transparency

These documents were developed collaboratively through the NTIA Multistakeholder Process on Software Component Transparency and are hosted on the NTIA Software Bill of Materials page.

SBOM FAQ

November 2020 [original] [local]

Outlines detailed information, benefits, and commonly asked questions.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 2

  •  
  •