logoalt Hacker News

LoganDarktoday at 3:39 AM1 replyview on HN

> what is it that SBOM is used for that lockfiles aren’t?

Compliance. The article mentions "the EU’s Cyber Resilience Act will push vendors toward providing SBOMs", and having package managers generate SBOMs directly would certainly be convenient for that.


Replies

jlubawytoday at 5:35 AM

The FDA also requires SBOMs as of a few years ago for medical device software.